cvs: phpweb / error.php /include errors.inc
| From: | Hannes Magnusson | Date: | Thu, 31 May 2007 17:10:45 +0000 |
| Subject: | cvs: phpweb / error.php /include errors.inc | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-35551@lists.php.net to get a copy of this message | ||
bjori Thu May 31 17:10:45 2007 UTC
Modified files:
/phpweb error.php
/phpweb/include errors.inc
Log:
Sanity check the requested mirror
# Prevents blind redirects to external domains
http://cvs.php.net/viewvc.cgi/phpweb/error.php?r1=1.64&r2=1.65&diff_format=u
Index: phpweb/error.php
diff -u phpweb/error.php:1.64 phpweb/error.php:1.65
--- phpweb/error.php:1.64 Fri Mar 30 13:57:47 2007
+++ phpweb/error.php Thu May 31 17:10:45 2007
@@ -1,6 +1,6 @@
<?php
-// $Id: error.php,v 1.64 2007/03/30 13:57:47 bjori Exp $
+// $Id: error.php,v 1.65 2007/05/31 17:10:45 bjori Exp $
/*
@@ -150,6 +150,11 @@
// Some other mirror is selected
else { $mr = "http://{$dlinfo[2]}/"; }
+ // Check if that mirror really exists if not, bail out
+ if(!isset($MIRRORS[$mr])) {
+ error_nomirror($mr);
+ exit;
+ }
// Start the download process
status_header(200);
include $_SERVER['DOCUMENT_ROOT'] . "/include/do-download.inc";
http://cvs.php.net/viewvc.cgi/phpweb/include/errors.inc?r1=1.6&r2=1.7&diff_format=u
Index: phpweb/include/errors.inc
diff -u phpweb/include/errors.inc:1.6 phpweb/include/errors.inc:1.7
--- phpweb/include/errors.inc:1.6 Tue Sep 19 15:41:49 2006
+++ phpweb/include/errors.inc Thu May 31 17:10:45 2007
@@ -1,5 +1,5 @@
<?php
-// $Id: errors.inc,v 1.6 2006/09/19 15:41:49 bjori Exp $
+// $Id: errors.inc,v 1.7 2007/05/31 17:10:45 bjori Exp $
/*
This script provides functions to print out
@@ -51,6 +51,18 @@
exit;
}
+// There is no such mirror
+function error_nomirror($mirror) {
+ site_header("No such mirror", array("noindex"));
+ echo "<h1>No such mirror</h1>\n<p>The mirror you tried to access (" .
+ htmlspecialchars($mirror) .
+ ") is not registered php.net mirror. Please check back later," .
+ " or if the problem persist, " .
+ "<a href=\"/contact.php\">contact the
webmasters</a>.</p>\n";
+ site_footer();
+ exit;
+}
+
// Send out a proper status header
function status_header($num)
{
@@ -69,3 +81,4 @@
return TRUE;
}
+