diff --git a/block_res/server.js b/block_res/server.js index ffb9e68..d6e2763 100644 --- a/block_res/server.js +++ b/block_res/server.js @@ -11,6 +11,11 @@ const port = 3000; // var pageHtml = require('./test.html'); const server = http.createServer((req, res) => { + if (path.normalize(decodeURI(req.url)) !== decodeURI(req.url)) { + res.statusCode = 403; + res.end(); + return; + } res.statusCode = 200; var url = req.url === '/' ? '/test.html' : req.url;