mirror of
https://git.tt-rss.org/git/tt-rss.git
synced 2025-12-13 01:46:00 +00:00
DiskCache: more strict checking for input filenames, getUrl() is no longer static
This commit is contained in:
@@ -1202,13 +1202,7 @@ class Handler_Public extends Handler {
|
||||
}
|
||||
|
||||
function cached_url() {
|
||||
$filename = $_GET['file'];
|
||||
|
||||
if (strpos($filename, "/") !== FALSE) {
|
||||
list ($cache_dir, $filename) = explode("/", $filename, 2);
|
||||
} else {
|
||||
$cache_dir = "images";
|
||||
}
|
||||
list ($cache_dir, $filename) = explode("/", $_GET["file"], 2);
|
||||
|
||||
$cache = new DiskCache($cache_dir);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user