MDL-30400 lti: Fixing warning in OAuthBodyPost
This would have only shown up if the tool provider didn't set the content-type header, which I don't think is valid to begin with. (amended by integrator to follow coding style rules)
This commit is contained in:
committed by
Eloy Lafuente (stronk7)
parent
ab83fa53fd
commit
cc6a4b0ecd
@@ -83,8 +83,10 @@ function handleOAuthBodyPOST($oauth_consumer_key, $oauth_consumer_secret, $body,
|
||||
}
|
||||
|
||||
// Must reject application/x-www-form-urlencoded
|
||||
if ($request_headers['Content-type'] == 'application/x-www-form-urlencoded' ) {
|
||||
throw new Exception("OAuth request body signing must not use application/x-www-form-urlencoded");
|
||||
if (isset($request_headers['Content-type'])) {
|
||||
if ($request_headers['Content-type'] == 'application/x-www-form-urlencoded' ) {
|
||||
throw new Exception("OAuth request body signing must not use application/x-www-form-urlencoded");
|
||||
}
|
||||
}
|
||||
|
||||
if (@substr($request_headers['Authorization'], 0, 6) == "OAuth ") {
|
||||
|
||||
Reference in New Issue
Block a user