diff --git a/svr.js b/svr.js index 3dd6625..23d84b2 100644 --- a/svr.js +++ b/svr.js @@ -1311,7 +1311,7 @@ function sanitizeURL(resource) { // Convert backslashes to slashes and remove duplicate slashes sanitizedResource = sanitizedResource.replace(/\\/g, "/").replace(/\/+/g, "/"); // Handle relative navigation (e.g., "/./", "/../", "../", "./"), also remove trailing dots in paths - sanitizedResource = sanitizedResource.replace(/\/\.(?:\.{2,})?(?=$|\/)/g, "").replace(/([^.\/])\.+(?=$|\/)/g, "$1"); + sanitizedResource = sanitizedResource.replace(/\/\.(?:\.{2,})?(?=\/|$)/g, "").replace(/([^.\/])\.+(?=\/|$)/g, "$1"); while (sanitizedResource.match(/\/(?!\.\.\/)[^\/]+\/\.\.(?=\/|$)/g)) { sanitizedResource = sanitizedResource.replace(/\/(?!\.\.\/)[^\/]+\/\.\.(?=\/|$)/g, ""); }