Permalink
Browse files

MDL-30042: Sanitize httpwwwroot in mnet jump

  • Loading branch information...
1 parent 919e659 commit f6d6e5446d6da60a867dc00c403dd04b90b7552e @andrewnicols andrewnicols committed Nov 7, 2011
Showing with 7 additions and 0 deletions.
  1. +7 −0 auth/mnet/jump.php
View
@@ -37,6 +37,13 @@
// If hostid hasn't been specified, try getting it using wwwroot
if (!$hostid) {
+ $hostwwwroot = trim($hostwwwroot);
+ $hostwwwroot = rtrim($hostwwwroot, '/');
+
+ // ensure the wwwroot starts with a http or https prefix
+ if (strtolower(substr($hostwwwroot, 0, 4)) != 'http') {
+ $hostwwwroot = 'http://'.$hostwwwroot;
+ }
$hostid = $DB->get_field('mnet_host', 'id', array('wwwroot' => $hostwwwroot));
}

0 comments on commit f6d6e54

Please sign in to comment.