MDL-21233 removing sloppy out_returnurl() from public api, it is considered a bad practise to pass around urls through page parameters, sorry
This commit is contained in:
+8
-1
@@ -893,8 +893,15 @@ class block_manager {
|
||||
|
||||
// Assign roles icon.
|
||||
if (has_capability('moodle/role:assign', $block->context)) {
|
||||
//TODO: please note it is sloppy to pass urls through page parameters!!
|
||||
// it is shortened because some web servers (e.g. IIS by default) give
|
||||
// a 'security' error if you try to pass a full URL as a GET parameter in another URL.
|
||||
|
||||
$return = $this->out(false, array(), false);
|
||||
$return = str_replace($CFG->wwwroot . '/', '', $return);
|
||||
|
||||
$controls[] = array('url' => $CFG->wwwroot . '/' . $CFG->admin .
|
||||
'/roles/assign.php?contextid=' . $block->context->id . '&returnurl=' . urlencode($this->page->url->out_returnurl()),
|
||||
'/roles/assign.php?contextid=' . $block->context->id . '&returnurl=' . urlencode($return),
|
||||
'icon' => 'i/roles', 'caption' => get_string('assignroles', 'role'));
|
||||
}
|
||||
|
||||
|
||||
@@ -534,30 +534,6 @@ class moodle_url {
|
||||
return $this->out(false, null, false);
|
||||
}
|
||||
|
||||
/**
|
||||
* Return a URL relative to $CFG->wwwroot.
|
||||
*
|
||||
* Throws an exception if this URL does not start with $CFG->wwwroot.
|
||||
*
|
||||
* The main use for this is when you want to pass a returnurl from one script to another.
|
||||
* In this case the returnurl should be relative to $CFG->wwwroot for two reasons.
|
||||
* First, it is shorter. More imporatantly, some web servers (e.g. IIS by default)
|
||||
* give a 'security' error if you try to pass a full URL as a GET parameter in another URL.
|
||||
*
|
||||
* @return string the URL relative to $CFG->wwwroot. Note, you will need to urlencode
|
||||
* this result if you are outputting a URL manually (but not if you are adding
|
||||
* it to another moodle_url).
|
||||
*/
|
||||
public function out_returnurl() {
|
||||
global $CFG;
|
||||
$fulluri = $this->out(false, array(), false);
|
||||
$uri = str_replace($CFG->wwwroot . '/', '', $fulluri);
|
||||
if ($uri == $fulluri) {
|
||||
throw new coding_exception('This URL (' . $fulluri . ') is not relative to $CFG->wwwroot.');
|
||||
}
|
||||
return $uri;
|
||||
}
|
||||
|
||||
/**
|
||||
* Output action url with sesskey
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user