Permalink
Browse files

Making custom scripts path generic so it is not forced to be in the

dataroot directory which is writable by the web server.
Path cleaned to avoid relative directory links.
  • Loading branch information...
ikawhero
ikawhero committed Feb 23, 2006
1 parent 7b5aa1b commit 9677eb79c5b4f214b23b1aa31c33e3f1fafbc2b8
Showing with 8 additions and 4 deletions.
  1. +3 −2 config-dist.php
  2. +5 −2 lib/moodlelib.php
View
@@ -214,7 +214,7 @@
// $CFG->filtermatchoneperpage = true;
//
// Enabling this will allow custom scripts to replace existing moodle scripts.
// For example: if $CFG->dataroot/customscripts/course/view.php exists then
// For example: if $CFG->customscripts/course/view.php exists then
// it will be used instead of $CFG->wwwroot/course/view.php
// At present this will only work for files that include config.php and are called
// as part of the url (index.php is implied).
@@ -226,7 +226,8 @@
// Warning: Replacing standard moodle scripts may pose security risks and/or may not
// be compatible with upgrades. Use this option only if you are aware of the risks
// involved.
// $CFG->customscripts = true;
// Specify the full directory path to the custom scripts
// $CFG->customscripts = '/home/example/customscripts';
//
// Performance profiling
//
View
@@ -6935,8 +6935,11 @@ function custom_script_path($urlpath='') {
if (!$urlpath) return false;
}
// Strip wwwroot out
$scriptpath = str_replace($CFG->wwwroot, $CFG->dataroot.'/customscripts', $urlpath);
/// Strip wwwroot out
$scriptpath = str_replace($CFG->wwwroot, $CFG->customscripts, $urlpath);
/// Clean the path
$scriptpath = clean_param($scriptpath, PARAM_PATH);
/// Strip the query string out
$parts = parse_url($scriptpath);

0 comments on commit 9677eb7

Please sign in to comment.