diff --git a/modules/api/views.js b/modules/api/views.js index 4669aab12..f0c71d8b8 100644 --- a/modules/api/views.js +++ b/modules/api/views.js @@ -107,7 +107,7 @@ function processInitialErrors(uri, next) { return true; } - if (/^(https?:\/\/)?\./i.test(uri)) { + if (/^(https?:\/\/)?(\.|\/|~)/i.test(uri)) { next(new utils.HttpError(400, "file paths are not accepted")); return true; }