This takes PathNormalizer from Kestrel to normalize the request path and prevent traversals. (e.g. "/./" and "/../"). In 2.1 only HttpSys was affected (https://dev.azure.com/dnceng/internal/_git/aspnet-AspNetCore/pullrequest/1480). In 2.2 HttpSys and IIS-in-proc share this code (with additional tests). In 3.0 we'll refactor it to use more shared source across all three servers. |
||
|---|---|---|
| .. | ||
| Antiforgery | ||
| Azure | ||
| DataProtection | ||
| DefaultBuilder | ||
| Features/JsonPatch | ||
| Framework | ||
| Hosting | ||
| Html/Abstractions | ||
| Http | ||
| Identity | ||
| Installers | ||
| JavaScriptServices | ||
| Middleware | ||
| MusicStore | ||
| Mvc | ||
| PackageArchive | ||
| Razor | ||
| Security | ||
| Servers | ||
| Shared | ||
| SignalR | ||
| SiteExtensions | ||
| Templating | ||
| Tools | ||
| submodules | ||