elongstreet88
elongstreet88
Allows "/latest" to be specified.
Fixes https://github.com/billchurch/webssh2/issues/345 `http://localhost:2222/ssh/host/mydevice.local?header=` Before: data:image/s3,"s3://crabby-images/e4c59/e4c595294070e09971a32f2a9767d47bd92b0e4e" alt="image" After: Note - This could be breaking if someone is using the header for HTML rendering, however, i would say this is still justified.
You can execute a xss using at least the header url param (didnt check others, but assume the same for anything page rendering). Ex: `http://localhost:2222/ssh/host/mydevice.local?header=` Output: The params would need...