InternalUrlValidator: prevent circumvention by URLs on the same VHost
This commit is contained in:
parent
e381b1e439
commit
c2f74d49cb
|
@ -16,7 +16,7 @@ class InternalUrlValidator extends Zend_Validate_Abstract
|
|||
*/
|
||||
public function isValid($value)
|
||||
{
|
||||
if (Url::fromPath($value)->isExternal()) {
|
||||
if (Url::fromPath($value)->getRelativeUrl() === '') {
|
||||
$this->_error('IS_EXTERNAL');
|
||||
|
||||
return false;
|
||||
|
|
Loading…
Reference in New Issue