mirror of
https://github.com/iv-org/invidious.git
synced 2024-12-18 20:24:36 -05:00
Fix input validation
This commit is contained in:
parent
a5cc66e060
commit
0b17f68eba
@ -82,7 +82,7 @@ module Invidious::Routes::API::V1::Authenticated
|
||||
end
|
||||
|
||||
id = env.params.url["id"]
|
||||
if !id.match(/[a-zA-Z0-9_-]{11}/)
|
||||
if !id.match(/^[a-zA-Z0-9_-]{11}$/)
|
||||
return error_json(400, "Invalid video id.")
|
||||
end
|
||||
|
||||
@ -98,7 +98,7 @@ module Invidious::Routes::API::V1::Authenticated
|
||||
end
|
||||
|
||||
id = env.params.url["id"]
|
||||
if !id.match(/[a-zA-Z0-9_-]{11}/)
|
||||
if !id.match(/^[a-zA-Z0-9_-]{11}$/)
|
||||
return error_json(400, "Invalid video id.")
|
||||
end
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user