Don't check referrer for html files

This commit is contained in:
shortcutme 2017-05-11 18:00:57 +02:00
parent 47245f485a
commit 27a582634f
No known key found for this signature in database
GPG key ID: 5B63BAE6CB9613AE

View file

@ -366,7 +366,7 @@ class UiRequest(object):
if wrapper_nonce not in self.server.wrapper_nonces: if wrapper_nonce not in self.server.wrapper_nonces:
return self.error403("Wrapper nonce error. Please reload the page.") return self.error403("Wrapper nonce error. Please reload the page.")
self.server.wrapper_nonces.remove(self.get["wrapper_nonce"]) self.server.wrapper_nonces.remove(self.get["wrapper_nonce"])
else:
referer = self.env.get("HTTP_REFERER") referer = self.env.get("HTTP_REFERER")
if referer and path_parts: # Only allow same site to receive media if referer and path_parts: # Only allow same site to receive media
if not self.isMediaRequestAllowed(path_parts["request_address"], referer): if not self.isMediaRequestAllowed(path_parts["request_address"], referer):