From 3d3f23ec9e6b763101906459eea40b0475f46e49 Mon Sep 17 00:00:00 2001 From: Andy Hsu <i@nn.ci> Date: Tue, 7 Mar 2023 14:13:39 +0800 Subject: [PATCH] fix: upload check if disable sub folder (close #3741) --- server/middlewares/fsup.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server/middlewares/fsup.go b/server/middlewares/fsup.go index 809e8f299eb..2aa7fca6d03 100644 --- a/server/middlewares/fsup.go +++ b/server/middlewares/fsup.go @@ -35,7 +35,7 @@ func FsUp(c *gin.Context) { return } } - if !(common.CanAccess(user, meta, path, password) && (user.CanWrite() || common.CanWrite(meta, path))) { + if !(common.CanAccess(user, meta, path, password) && (user.CanWrite() || common.CanWrite(meta, stdpath.Dir(path)))) { common.ErrorResp(c, errs.PermissionDenied, 403) c.Abort() return