Skip to content

Conversation

aldas
Copy link
Contributor

@aldas aldas commented Nov 7, 2023

Security

  • 'c.Attachment' and 'c.Inline' should escape filename in 'Content-Disposition' header to avoid 'Reflect File Download' vulnerability. #2541

Enhancements

  • Tests: refactor context tests to be separate functions #2540
  • Proxy middleware: reuse echo request context #2537
  • Mark unmarshallable yaml struct tags as ignored #2536

@aldas aldas merged commit 4b26cde into labstack:master Nov 7, 2023
@aldas aldas deleted the changelog_4_11_3 branch November 7, 2023 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant