MDL-62889 message_popup: redirect to notification page if url is empty
If you pass a URL that is not a valid URL (for example ';') it is cleaned to an empty string which redirects to $CFG->wwwroot/message/output/popup/ which is not a valid page.
This commit is contained in:
@@ -31,10 +31,15 @@ if (isguestuser()) {
|
||||
}
|
||||
|
||||
$notificationid = required_param('notificationid', PARAM_INT);
|
||||
$redirecturl = optional_param('redirecturl', $CFG->wwwroot, PARAM_URL);
|
||||
$redirecturl = optional_param('redirecturl', '', PARAM_URL);
|
||||
|
||||
$notification = $DB->get_record('message', array('id' => $notificationid, 'notification' => 1));
|
||||
|
||||
// If the redirect URL after filtering is empty, or it was never passed, then redirect to the notification page.
|
||||
if (empty($redirecturl)) {
|
||||
$redirecturl = new moodle_url('/message/output/popup/notifications.php', ['notificationid' => $notificationid]);
|
||||
}
|
||||
|
||||
// If found, is unread, so mark read if belongs to this user.
|
||||
if ($notification) {
|
||||
if ($USER->id == $notification->useridto) {
|
||||
|
||||
Reference in New Issue
Block a user