diff options
| author | dakkar <dakkar@thenautilus.net> | 2025-04-28 15:00:00 +0100 |
|---|---|---|
| committer | dakkar <dakkar@thenautilus.net> | 2025-04-28 15:31:28 +0100 |
| commit | 4981e5ba36bf9286a7bb9ff1dc6a10d7e3855241 (patch) | |
| tree | 5b00e9f161a2db8f688de1a0dfd3f86fd988592e /packages/frontend/src/aiscript/api.ts | |
| parent | fix null checks for background in UserEntityService.ts (diff) | |
| parent | merge: Merge stable into develop (!971) (diff) | |
| download | sharkey-4981e5ba36bf9286a7bb9ff1dc6a10d7e3855241.tar.gz sharkey-4981e5ba36bf9286a7bb9ff1dc6a10d7e3855241.tar.bz2 sharkey-4981e5ba36bf9286a7bb9ff1dc6a10d7e3855241.zip | |
Merge branch 'develop' into merge/2025-03-24
Diffstat (limited to 'packages/frontend/src/aiscript/api.ts')
| -rw-r--r-- | packages/frontend/src/aiscript/api.ts | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/packages/frontend/src/aiscript/api.ts b/packages/frontend/src/aiscript/api.ts index e7e396023d..08ba89dd9d 100644 --- a/packages/frontend/src/aiscript/api.ts +++ b/packages/frontend/src/aiscript/api.ts @@ -68,7 +68,7 @@ export function createAiScriptEnv(opts: { storageKey: string, token?: string }) }), 'Mk:api': values.FN_NATIVE(async ([ep, param, token]) => { utils.assertString(ep); - if (ep.value.includes('://')) { + if (ep.value.includes('://') || ep.value.includes('..')) { throw new errors.AiScriptRuntimeError('invalid endpoint'); } if (token) { |