settings.MEDIA_ROOT,
self.get_directory(),
filename))
- if not path.startswith(settings.MEDIA_ROOT):
+ if not path.startswith(os.path.abspath(settings.MEDIA_ROOT)):
raise Http404
if filename:
if not path.startswith(self.get_safe_path()):
files = []
path = self.get_safe_path()
if os.path.isdir(path):
- for f in os.listdir(path):
+ for f in sorted(os.listdir(path)):
file_info = {
"name": f,
}