05c067c99142387814458e0d7d8d00ca9221a91a
Move the '..' detection to operate on the raw path string before normalization, ensuring path traversal attempts are caught even when normpath would collapse them. Also apply the same early check to api_parsed_url.path in proxy_request, preventing bypass via normalized path segments.
Rantii
DevRant client built with vanilla JavaScript, Web Components, and CSS.
Requirements
- Python 3.8+
- aiohttp (
pip install aiohttp)
Run
python3 proxy.py
Open http://localhost:8101
Features
- Browse rants, weekly challenges, collabs, stories
- User profiles and notifications
- Voting, commenting, posting
- Search
- 7 themes: dark, light, black, white, ocean, forest, sunset
- PWA installable
- Offline support via service worker
Structure
rantii/
├── index.html
├── proxy.py
├── manifest.json
├── sw.js
├── css/
│ ├── base.css
│ ├── variables.css
│ ├── themes/
│ └── components/
├── js/
│ ├── app.js
│ ├── api/
│ ├── services/
│ ├── components/
│ ├── pages/
│ └── utils/
├── lib/
│ ├── marked.min.js
│ └── highlight.min.js
└── assets/
Author
retoor retoor@molodetz.nl
Description
devRant front-end with markdown, syntax highlighting, url previews and youtube / image embedding.
672 KiB
Languages
JavaScript
73.6%
CSS
19.1%
Python
6.2%
HTML
1%