Disallow minor version numbers in URLs for security page.
authorJonathan S. Katz <jonathan.katz@excoventures.com>
Wed, 12 Sep 2018 16:44:22 +0000 (12:44 -0400)
committerJonathan S. Katz <jonathan.katz@excoventures.com>
Wed, 12 Sep 2018 16:44:22 +0000 (12:44 -0400)
pgweb/urls.py

index 64caf1e92af94074a0ea93c3b4ae4516a1dd2787..9b6ae042dd40d9fc53854624c2736addd5f9a89a 100644 (file)
@@ -74,7 +74,7 @@ urlpatterns = [
        url(r'^search/$', pgweb.search.views.search),
 
        url(r'^support/security/$', pgweb.security.views.index),
-       url(r'^support/security/([\d\.]+)/$', pgweb.security.views.version),
+       url(r'^support/security/(\d\.\d|\d{2})/$', pgweb.security.views.version),
        url(r'^support/security_archive/$', RedirectView.as_view(url='/support/security/', permanent=True)),
 
        url(r'^support/professional_(support|hosting)/$', pgweb.profserv.views.root),