Skip to content

Conversation

@jglick
Copy link
Member

@jglick jglick commented Sep 11, 2025

Alternative to hacky hand-coded parser used in jenkinsci/credentials-plugin#651. Looks challenging to write given the large number of path travsersal options. Also need to be cautious about malicious Referer headers: need to use the same blocking logic used during request processing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant