miniblog.

← Back to all posts
2
Go has an os.Root API that allows you to enforce all paths are subdirectories of a given root. It fixes users accessing foo/../../../etc/passwd and similar. Seems like a really nice solution for a relatively common problem.