diff --git a/index.js b/index.js index dc46df5..c069f27 100644 --- a/index.js +++ b/index.js @@ -261,11 +261,11 @@ app.get('/jobs-status', async (req, res) => { })))); }); -app.get('/download/:filename', async (req, res) => { +app.get('/download', async (req, res) => { try { - const { filename } = req.params; + const { filename } = req.query; - if (filename.includes('..') || filename.includes('/') || filename.includes('\\')) { + if (filename.includes('..') || filename.includes('\\')) { return res.status(400).json({ error: 'Invalid filename' }); }