MDL-48929 repository_filesystem: Valide relative path against realpath
On Windows systems, there could have been a mix of back and forward slashes, causing the validation of the relative path to fail. Now we will always get the realpath before comparing.
This commit is contained in:
committed by
Frederic Massart
parent
146c80d338
commit
ce534d5dfa
@@ -575,7 +575,7 @@ class repository_filesystem extends repository {
|
||||
$fullrelativefilepath = realpath($this->get_rootpath().$basepath.$relativepath);
|
||||
|
||||
// Sanity check to make sure this path is inside this repository and the file exists.
|
||||
if (strpos($fullrelativefilepath, $this->get_rootpath()) === 0 && file_exists($fullrelativefilepath)) {
|
||||
if (strpos($fullrelativefilepath, realpath($this->get_rootpath())) === 0 && file_exists($fullrelativefilepath)) {
|
||||
send_file($fullrelativefilepath, basename($relativepath), null, 0);
|
||||
}
|
||||
}
|
||||
@@ -665,4 +665,4 @@ function repository_filesystem_cron() {
|
||||
$instances[$itemid]->remove_obsolete_thumbnails($files);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user