mirror of
https://github.com/Icinga/icingaweb2.git
synced 2025-07-23 13:54:26 +02:00
InternalUrlValidator: prevent circumvention by URLs on the same VHost
This commit is contained in:
parent
e381b1e439
commit
c2f74d49cb
@ -16,7 +16,7 @@ class InternalUrlValidator extends Zend_Validate_Abstract
|
|||||||
*/
|
*/
|
||||||
public function isValid($value)
|
public function isValid($value)
|
||||||
{
|
{
|
||||||
if (Url::fromPath($value)->isExternal()) {
|
if (Url::fromPath($value)->getRelativeUrl() === '') {
|
||||||
$this->_error('IS_EXTERNAL');
|
$this->_error('IS_EXTERNAL');
|
||||||
|
|
||||||
return false;
|
return false;
|
||||||
|
Loading…
x
Reference in New Issue
Block a user