Remove /media access
This commit is contained in:
parent
72f91a2816
commit
d65c7d05a4
2 changed files with 1 additions and 3 deletions
|
@ -25,7 +25,7 @@ class WaitForPageLoad(object):
|
|||
@pytest.mark.webtest
|
||||
class TestWeb:
|
||||
def testFileSecurity(self, site_url):
|
||||
assert "Forbidden" in urllib.urlopen("%s/media/./sites.json" % site_url).read()
|
||||
assert "Not Found" in urllib.urlopen("%s/media/./sites.json" % site_url).read()
|
||||
assert "Forbidden" in urllib.urlopen("%s/media/../config.py" % site_url).read()
|
||||
assert "Forbidden" in urllib.urlopen("%s/media/1EU1tbG9oC1A8jz2ouVwGZyQ5asrNsE4Vr/../sites.json" % site_url).read()
|
||||
assert "Forbidden" in urllib.urlopen("%s/media/1EU1tbG9oC1A8jz2ouVwGZyQ5asrNsE4Vr/..//sites.json" % site_url).read()
|
||||
|
|
|
@ -67,8 +67,6 @@ class UiRequest(object):
|
|||
# uimedia within site dir (for chrome extension)
|
||||
path = re.sub(".*?/uimedia/", "/uimedia/", path)
|
||||
return self.actionUiMedia(path)
|
||||
elif path.startswith("/media"):
|
||||
return self.actionSiteMedia(path)
|
||||
# Websocket
|
||||
elif path == "/Websocket":
|
||||
return self.actionWebsocket()
|
||||
|
|
Loading…
Reference in a new issue