mirror of
https://github.com/firefly-iii/firefly-iii.git
synced 2025-02-25 18:45:27 -06:00
Fix unsecure redirect code.
This commit is contained in:
@@ -45,7 +45,6 @@ class StartFireflySession extends StartSession
|
||||
$url = $request->fullUrl();
|
||||
$forbiddenWords = strpos($url, 'offline') || strpos($url, 'jscript') || strpos($url, 'delete') || strpos($url, '/login') || strpos($url, '/json') || strpos($url, 'serviceworker') || strpos($url, '/attachments/view');
|
||||
|
||||
// also stop remembering "delete" URL's.
|
||||
if (false === $forbiddenWords
|
||||
&& 'GET' === $request->method()
|
||||
&& !$request->ajax()) {
|
||||
|
||||
Reference in New Issue
Block a user