Nonce checking moved to route command
This commit is contained in:
parent
74b2408668
commit
1f5db0aa24
1 changed files with 0 additions and 5 deletions
|
@ -445,11 +445,6 @@ class UiRequest(object):
|
||||||
|
|
||||||
# Check wrapper nonce
|
# Check wrapper nonce
|
||||||
content_type = self.getContentType(path_parts["inner_path"])
|
content_type = self.getContentType(path_parts["inner_path"])
|
||||||
if "htm" in content_type and not header_noscript: # Valid nonce must present to render html files
|
|
||||||
wrapper_nonce = self.get.get("wrapper_nonce")
|
|
||||||
if wrapper_nonce not in self.server.wrapper_nonces:
|
|
||||||
return self.error403("Wrapper nonce error. Please reload the page.")
|
|
||||||
self.server.wrapper_nonces.remove(self.get["wrapper_nonce"])
|
|
||||||
else:
|
else:
|
||||||
referer = self.env.get("HTTP_REFERER")
|
referer = self.env.get("HTTP_REFERER")
|
||||||
if referer and path_parts: # Only allow same site to receive media
|
if referer and path_parts: # Only allow same site to receive media
|
||||||
|
|
Loading…
Reference in a new issue