From 08ffda43bc68b63c29db0bb95e00337d3f1e41f7 Mon Sep 17 00:00:00 2001 From: Kyle Drake Date: Fri, 8 Aug 2025 14:29:24 -0500 Subject: [PATCH] escape thumbnail path --- models/site.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/models/site.rb b/models/site.rb index 8d8a0112..1931d817 100644 --- a/models/site.rb +++ b/models/site.rb @@ -1725,7 +1725,7 @@ class Site < Sequel::Model def thumbnail_url(path, resolution) path[0] = '' if path[0] == '/' - "#{THUMBNAILS_URL_ROOT}/#{sharding_dir}/#{values[:username]}/#{path}.#{resolution}.webp" + "#{THUMBNAILS_URL_ROOT}/#{sharding_dir}/#{values[:username]}/#{self.class.escape_path(path)}.#{resolution}.webp" end def to_rss