Static and session security fixes for Plug

from Redirecting…

While I don’t believe this poises a security issue in OTP itself, I believe the platform would be safer if it raised when a string or binary with a null byte is given anytime we are interacting with the filesystem.

so you were mostly right but it is indeed a relatively minor issue :slight_smile:

2 Likes