Skip to content

Don't bypass file containment checks for disabled file roots. - #8131

Open
labkey-klum wants to merge 6 commits into
release26.3-SNAPSHOTfrom
26.3_fb_download_file_link
Open

labkey-klum wants to merge 6 commits into
release26.3-SNAPSHOTfrom
26.3_fb_download_file_link

Conversation

@labkey-klum

@labkey-klum labkey-klum commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Rationale

https://github.com/LabKey/internal-issues/issues/1463

Introduces a new service method to return configured file root paths regardless of whether the root has been disabled at the folder level. This closes off the primary vulnerability for the above issue. Also added an additional check in DownloadFileLinkAction to ensure the table column requested has the same property URI specified on the request.

Related Pull Requests

LabKey/testAutomation#3224

@labkey-alan labkey-alan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fixes look correct to me

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants