style: gofmt normalization — no logic changes
gofmt -w across the controller tree (46 files) so gofmt -l is empty — disarms the
formatting landmine where a targeted edit + accidental gofmt -w swept ~46 unrelated
files. Pure formatting: whitespace + gofmt's optional-semicolon removal in reflowed
inline closures. One doc comment reworded ('' -> 'the empty string') to avoid gofmt's
Go-1.19 doc-comment typographic substitition ('' -> curly quote) muddying its meaning.
No build/vet/test behavior change.
This commit is contained in:
@@ -50,13 +50,13 @@ func TestFabDownload_TraversalGuardAndCleanup(t *testing.T) {
|
||||
}
|
||||
|
||||
refused := []string{
|
||||
"..%2Fdecoy.fab", // ../decoy.fab
|
||||
"..%5Cdecoy.fab", // ..\decoy.fab
|
||||
"%2Fetc%2Fpasswd", // absolute path
|
||||
"sub%2Fx.fab", // separator
|
||||
"..", // bare traversal
|
||||
".hidden.fab", // not the exporter's naming (leading dot)
|
||||
"x.txt", // not a .fab
|
||||
"..%2Fdecoy.fab", // ../decoy.fab
|
||||
"..%5Cdecoy.fab", // ..\decoy.fab
|
||||
"%2Fetc%2Fpasswd", // absolute path
|
||||
"sub%2Fx.fab", // separator
|
||||
"..", // bare traversal
|
||||
".hidden.fab", // not the exporter's naming (leading dot)
|
||||
"x.txt", // not a .fab
|
||||
}
|
||||
for _, f := range refused {
|
||||
if rr := fetchDownload(s, f); rr.Code != http.StatusBadRequest {
|
||||
|
||||
Reference in New Issue
Block a user