Permalink
Browse files

#2074 - Mirror some additional file_proxy checks in data_rest.

--HG--
extra : source : 752417004a5c988b09f1312c4e96f10dd11594b9
  • Loading branch information...
1 parent c926ed2 commit cbbcf1b4791762d7da0ea7b6c4f4b551a4d9caed @shadlaws shadlaws committed Jun 12, 2013
Showing with 6 additions and 1 deletion.
  1. +6 −1 modules/gallery/helpers/data_rest.php
@@ -25,7 +25,6 @@
class data_rest_Core {
static function get($request) {
$item = rest::resolve($request->url);
- access::required("view", $item);
$p = $request->params;
if (!isset($p->size) || !in_array($p->size, array("thumb", "resize", "full"))) {
@@ -36,10 +35,16 @@ static function get($request) {
// see if you should make the same change there as well.
if ($p->size == "full") {
+ if ($item->is_album()) {
+ throw new Kohana_404_Exception();
+ }
+ access::required("view_full", $item);
$file = $item->file_path();
} else if ($p->size == "resize") {
+ access::required("view", $item);
$file = $item->resize_path();
} else {
+ access::required("view", $item);
$file = $item->thumb_path();
}

0 comments on commit cbbcf1b

Please sign in to comment.