diff --git a/main.py b/main.py
index 91cbae3..0a6e740 100644
--- a/main.py
+++ b/main.py
@@ -44,8 +44,8 @@ class WebServer:
async def handle(self, reader: asyncio.StreamReader, writer: asyncio.StreamWriter) -> None:
addr = writer.get_extra_info("peername")
await self.log(self.conn_msg, addr)
- data = await reader.read(self._read_buffer)
- data = unquote(data.decode())
+ rdata = await reader.read(self._read_buffer)
+ data = rdata.decode()
if not data: return
real_addr = None
@@ -56,9 +56,14 @@ class WebServer:
if real_addr and self.proxied:
addr = (real_addr, addr[1])
+
request = data.split("\n")[0]
- file_name = request.split()[1][1:]
- file_path = os.path.join(self.directory, file_name)
+ parts = request.split()
+ if len(parts) < 2: return
+
+ path = unquote(parts[1])
+ file_name = path[1:] if path.startswith('/') else path
+ file_path = os.path.abspath(os.path.join(self.directory, file_name))
if os.path.isfile(file_path):
mime, _ = mimetypes.guess_type(file_path)
@@ -113,7 +118,7 @@ class WebServer:
modify_datetime = datetime.datetime.fromtimestamp(modify_time)
formatted_time = modify_datetime.strftime("%d.%m.%Y %H:%M:%S")
- files += f'{item} | {formatted_time}
'
+ files += f'{item} | {formatted_time}
\n'
resp = resp.replace("", files)
resp = resp.encode()