Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
I
intranet-filestorage
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
project-open
intranet-filestorage
Commits
5a3d1c0a
Commit
5a3d1c0a
authored
Jun 11, 2020
by
Frank Bergmann
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
- Improved security: Removed most [ns_conn form] calls in the system.
parent
81493010
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
3 additions
and
3 deletions
+3
-3
intranet-filestorage-procs.tcl
tcl/intranet-filestorage-procs.tcl
+1
-1
action.tcl
www/action.tcl
+2
-2
No files found.
tcl/intranet-filestorage-procs.tcl
View file @
5a3d1c0a
...
...
@@ -1607,7 +1607,7 @@ ad_proc -public im_filestorage_base_component { user_id object_id object_name ba
set return_url
[
im_url_with_query
]
if
{
""
==
$bread
_crum_path
}
{
set bread_crum_path
[
ns_set get
$bind
_vars
bread_crum_path
]
set bread_crum_path
[
im_opt_val -limit_to nohtml
bread_crum_path
]
}
if
{[
im_security_alert_check_path -location
"intranet-filestorage.im_filestorage_base_component"
-value
$bread
_crum_path
]}
{
set bread_crum_path
""
...
...
www/action.tcl
View file @
5a3d1c0a
...
...
@@ -67,7 +67,7 @@ array set perm_hash $perm_hash_array
foreach
var
[
ad_ns_set_keys
$bind
_vars
]
{
set value
[
ns_set get
$bind
_vars
$var
]
set value
[
im_opt_val -limit_to nohtml
$var
]
if
{[
regexp
{
first_line_flag
}
$var
]}
{
ns_set delkey
$bind
_vars
$var
}
...
...
@@ -679,7 +679,7 @@ Are you sure you really want to delete the following files?
set
ctr 0
foreach
var
[
ad_ns_set_keys
$bind
_vars
]
{
set value
[
ns_set get
$bind
_vars
$var
]
set value
[
im_opt_val -limit_to nohtml
$var
]
if
{
$ctr
> 0
}
{
append vars
"&"
}
append vars
"
$var
=
$value
\n
"
incr ctr
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment