Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Z
Zope
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
Kirill Smelkov
Zope
Commits
713a4f22
Commit
713a4f22
authored
Feb 09, 2000
by
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Made a change to the traverse() method to disallow traversal of the REQUEST.
parent
0816d3ba
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
7 additions
and
1 deletion
+7
-1
lib/python/ZPublisher/BaseRequest.py
lib/python/ZPublisher/BaseRequest.py
+7
-1
No files found.
lib/python/ZPublisher/BaseRequest.py
View file @
713a4f22
...
...
@@ -82,7 +82,7 @@
# attributions are listed in the accompanying credits file.
#
##############################################################################
__version__
=
'$Revision: 1.1
6
$'
[
11
:
-
2
]
__version__
=
'$Revision: 1.1
7
$'
[
11
:
-
2
]
from
string
import
join
,
split
,
find
,
rfind
,
lower
,
upper
from
urllib
import
quote
...
...
@@ -227,6 +227,10 @@ class BaseRequest:
if
response
is
None
:
response
=
self
.
response
debug_mode
=
response
.
debug_mode
# Make sure that REQUEST cannot be traversed.
if
find
(
path
,
'REQUEST'
)
>=
0
:
return
response
.
notFoundError
(
path
)
if
path
[:
1
]
!=
'/'
:
path
=
'/'
+
path
if
path
[
-
1
:]
!=
'/'
:
path
=
path
+
'/'
if
find
(
path
,
'/.'
)
>=
0
:
...
...
@@ -459,6 +463,8 @@ class BaseRequest:
"""
self
.
_held
=
self
.
_held
+
(
object
,)
def
old_validation
(
groups
,
request
,
auth
,
roles
=
UNSPECIFIED_ROLES
):
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment