mirror of
https://github.com/mailcow/mailcow-dockerized.git
synced 2026-09-01 08:27:09 +00:00
Improve template URI escaping and parameter handling
This commit is contained in:
@@ -89,7 +89,7 @@ $globalVariables = [
|
|||||||
'app_links' => $app_links,
|
'app_links' => $app_links,
|
||||||
'app_links_processed' => $app_links_processed,
|
'app_links_processed' => $app_links_processed,
|
||||||
'is_root_uri' => (parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH) == '/'),
|
'is_root_uri' => (parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH) == '/'),
|
||||||
'uri' => $_SERVER['REQUEST_URI'],
|
'uri' => parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH) ?: '/',
|
||||||
];
|
];
|
||||||
|
|
||||||
foreach ($globalVariables as $globalVariableName => $globalVariableValue) {
|
foreach ($globalVariables as $globalVariableName => $globalVariableValue) {
|
||||||
|
|||||||
@@ -13,7 +13,9 @@ $twig = new Environment($loader, [
|
|||||||
|
|
||||||
// functions
|
// functions
|
||||||
$twig->addFunction(new TwigFunction('query_string', function (array $params = []) {
|
$twig->addFunction(new TwigFunction('query_string', function (array $params = []) {
|
||||||
return http_build_query(array_merge($_GET, $params));
|
$allowed = ['lang', 'mobileconfig'];
|
||||||
|
$filtered = array_intersect_key($_GET, array_flip($allowed));
|
||||||
|
return http_build_query(array_merge($filtered, $params));
|
||||||
}));
|
}));
|
||||||
|
|
||||||
$twig->addFunction(new TwigFunction('is_uri', function (string $uri, string $where = null) {
|
$twig->addFunction(new TwigFunction('is_uri', function (string $uri, string $where = null) {
|
||||||
|
|||||||
@@ -193,7 +193,7 @@ $(window).scroll(function() {
|
|||||||
});
|
});
|
||||||
// Select language and reopen active URL without POST
|
// Select language and reopen active URL without POST
|
||||||
function setLang(sel) {
|
function setLang(sel) {
|
||||||
$.post( '{{ uri }}', {lang: sel} );
|
$.post( '{{ uri|escape("js") }}', {lang: sel} );
|
||||||
window.location.href = window.location.pathname + window.location.search;
|
window.location.href = window.location.pathname + window.location.search;
|
||||||
}
|
}
|
||||||
// FIDO2 functions
|
// FIDO2 functions
|
||||||
|
|||||||
Reference in New Issue
Block a user