mirror of
https://github.com/HelloZeroNet/ZeroNet.git
synced 2023-12-14 04:33:03 +01:00
Filter media referrer by original request address
This commit is contained in:
parent
04bed98a97
commit
835381fbb1
1 changed files with 2 additions and 1 deletions
|
@ -327,7 +327,8 @@ class UiRequest(object):
|
|||
|
||||
referer = self.env.get("HTTP_REFERER")
|
||||
if referer and path_parts: # Only allow same site to receive media
|
||||
if not self.isMediaRequestAllowed(path_parts["address"], referer):
|
||||
if not self.isMediaRequestAllowed(path_parts["request_address"], referer):
|
||||
self.log.error("Media referrer error: %s not allowed from %s" % (path_parts["address"], referer))
|
||||
return self.error403("Media referrer error") # Referrer not starts same address as requested path
|
||||
|
||||
if path_parts: # Looks like a valid path
|
||||
|
|
Loading…
Reference in a new issue