Skip to content

docs(security): use the Files API in the directory traversal example - #15678

Merged
miaulalala merged 1 commit into
masterfrom
fix/security-path-traversal-example
Oct 1, 2026
Merged

miaulalala merged 1 commit into
masterfrom
fix/security-path-traversal-example

Conversation

@miaulalala

@miaulalala miaulalala commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

The directory traversal example used the private OC_User API and wrote straight into the data directory. It now shows the Files API (IRootFolder::getUserFolder()->get()), which rejects .. paths.

AI-assisted (Claude Code).

🤖 Generated with Claude Code

The old example used the private OC_User API and wrote to the data
directory directly; the new one goes through IRootFolder.

Assisted-by: ClaudeCode:claude-opus-5-5
Signed-off-by: Anna Larch <[email protected]>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

📖 Documentation Preview

🔍 Open preview →

📄 1 changed documentation page

Last updated: Thu, 01 Oct 2026 16:04:00 GMT

@miaulalala

Copy link
Copy Markdown
Contributor Author

/backport to stable35

@miaulalala

Copy link
Copy Markdown
Contributor Author

/backport to stable34

@miaulalala
miaulalala merged commit 50e121b into master Oct 1, 2026
26 checks passed
@miaulalala
miaulalala deleted the fix/security-path-traversal-example branch October 1, 2026 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants