append referuri to base url to prevent redirects to arbitraty sites

This commit is contained in:
Uwe Steinmann 2021-06-21 08:58:22 +02:00
parent fff27af7e6
commit 0b9435d362

View File

@ -97,8 +97,7 @@ if(!$controller->run()) {
$user = $controller->getUser();
if (isset($referuri) && strlen($referuri)>0) {
// header("Location: http".((isset($_SERVER['HTTPS']) && (strcmp($_SERVER['HTTPS'],'off')!=0)) ? "s" : "")."://".$_SERVER['HTTP_HOST'] . $referuri);
header("Location: " . $referuri);
header("Location: " . getBaseUrl() . "/" . $referuri);
}
else {
header("Location: ".$settings->_httpRoot.(isset($settings->_siteDefaultPage) && strlen($settings->_siteDefaultPage)>0 ? $settings->_siteDefaultPage : "out/out.ViewFolder.php?folderid=".($user->getHomeFolder() ? $user->getHomeFolder() : $settings->_rootFolderID)));