mirror of
https://github.com/ankitects/anki.git
synced 2025-09-18 22:12:21 -04:00
Removed duplicated mediasrv.py security check and fixed invalid
command/path error message.
This commit is contained in:
parent
1218d109e8
commit
a99e455414
1 changed files with 1 additions and 8 deletions
|
@ -126,13 +126,6 @@ def allroutes(pathin):
|
||||||
|
|
||||||
try:
|
try:
|
||||||
if flask.request.method == "POST":
|
if flask.request.method == "POST":
|
||||||
if not pathin.startswith("_anki/"):
|
|
||||||
return flask.Response(
|
|
||||||
"Path for '%s - %s' is a security leak!" % (directory, path),
|
|
||||||
status=HTTPStatus.FORBIDDEN,
|
|
||||||
mimetype="text/plain",
|
|
||||||
)
|
|
||||||
|
|
||||||
if path == "graphData":
|
if path == "graphData":
|
||||||
body = request.data
|
body = request.data
|
||||||
data = graph_data(allroutes.mw.col, **from_json_bytes(body))
|
data = graph_data(allroutes.mw.col, **from_json_bytes(body))
|
||||||
|
@ -140,7 +133,7 @@ def allroutes(pathin):
|
||||||
data = allroutes.mw.col.backend.i18n_resources()
|
data = allroutes.mw.col.backend.i18n_resources()
|
||||||
else:
|
else:
|
||||||
return flask.Response(
|
return flask.Response(
|
||||||
"Path for '%s - %s' is a security leak!" % (directory, path),
|
"Post request to '%s - %s' is a security leak!" % (directory, path),
|
||||||
status=HTTPStatus.FORBIDDEN,
|
status=HTTPStatus.FORBIDDEN,
|
||||||
mimetype="text/plain",
|
mimetype="text/plain",
|
||||||
)
|
)
|
||||||
|
|
Loading…
Reference in a new issue