]> git.mxchange.org Git - quix0rs-gnu-social.git/commit
Ticket #2796: don't allow arbitrary overriding of the 'action' class and other parame...
authorBrion Vibber <brion@status.net>
Fri, 19 Nov 2010 23:30:52 +0000 (15:30 -0800)
committerBrion Vibber <brion@status.net>
Fri, 19 Nov 2010 23:30:52 +0000 (15:30 -0800)
commit4193a826d3500c1c8771e2a55ca197011fe637c8
treed2cff00e109e7f8d361c052b1452041457dc58b6
parentca55d6c514d4ecadbb7d3fdc4c618dfd9da4a786
Ticket #2796: don't allow arbitrary overriding of the 'action' class and other parameters pulled from the URL mapper.

This protects against oddities such as manual invocation of the ClientError action, which can spoof error messages.
index.php