mirror of
https://github.com/go-gitea/gitea
synced 2025-10-30 19:08:37 +00:00
From testing, I found that issue posters and users with repository write access are able to edit attachment names in a way that circumvents the instance-level file extension restrictions using the edit attachment APIs. This snapshot adds checks for these endpoints.
7.4 KiB
7.4 KiB