mirror of
https://github.com/Cockatrice/Cockatrice.git
synced 2026-09-28 00:42:19 -07:00
The local deck and replay browsers list every file in the folder, so a stray file (e.g. a PNG screenshot of a deck) can be parsed as a garbage plaintext deck, opened in the editor, and uploaded. The server also accepts oversized deck payloads with only silent truncation. Hide files that are not in a supported deck/replay format in the two QFileSystemModel views (directories stay visible), skip them when opening, reject them when uploading, and make the server reject deck uploads larger than MAX_FILE_LENGTH instead of truncating them. Co-authored-by: Lukas Brübach <Bruebach.Lukas@bdosecurity.de> |
||
|---|---|---|
| .. | ||
| docker | ||
| migrations | ||
| mysql-storage | ||
| resources | ||
| scripts | ||
| src | ||
| check_schema_version.sh | ||
| CMakeLists.txt | ||
| servatrice.desktop | ||
| servatrice.ini.example | ||
| servatrice.qrc | ||
| servatrice.rc | ||
| servatrice.sql | ||