diff --git a/src/Test/TestWeb.py b/src/Test/TestWeb.py index e1137dcf..5cc6825c 100644 --- a/src/Test/TestWeb.py +++ b/src/Test/TestWeb.py @@ -25,7 +25,7 @@ class WaitForPageLoad(object): @pytest.mark.webtest class TestWeb: def testFileSecurity(self, site_url): - assert "Forbidden" in urllib.urlopen("%s/media/./sites.json" % site_url).read() + assert "Not Found" in urllib.urlopen("%s/media/./sites.json" % site_url).read() assert "Forbidden" in urllib.urlopen("%s/media/../config.py" % site_url).read() assert "Forbidden" in urllib.urlopen("%s/media/1EU1tbG9oC1A8jz2ouVwGZyQ5asrNsE4Vr/../sites.json" % site_url).read() assert "Forbidden" in urllib.urlopen("%s/media/1EU1tbG9oC1A8jz2ouVwGZyQ5asrNsE4Vr/..//sites.json" % site_url).read() diff --git a/src/Ui/UiRequest.py b/src/Ui/UiRequest.py index ade12f58..af404c31 100644 --- a/src/Ui/UiRequest.py +++ b/src/Ui/UiRequest.py @@ -67,8 +67,6 @@ class UiRequest(object): # uimedia within site dir (for chrome extension) path = re.sub(".*?/uimedia/", "/uimedia/", path) return self.actionUiMedia(path) - elif path.startswith("/media"): - return self.actionSiteMedia(path) # Websocket elif path == "/Websocket": return self.actionWebsocket()