mirror of
https://github.com/vichan-devel/vichan.git
synced 2024-11-25 07:50:23 +01:00
Merge pull request #245 from forklessanon/patch-3
Security fix: Added defaults to the banned boards
This commit is contained in:
commit
0da5d13e7e
@ -603,6 +603,17 @@
|
||||
// How many ban appeals can be made for a single ban?
|
||||
$config['ban_appeals_max'] = 1;
|
||||
|
||||
// Blacklisted board names. Default values to protect existing folders in the core codebase.
|
||||
$config['banned_boards'] = array(
|
||||
'.git',
|
||||
'inc',
|
||||
'js',
|
||||
'static',
|
||||
'stylesheets',
|
||||
'templates',
|
||||
'tools'
|
||||
);
|
||||
|
||||
// Show moderator name on ban page.
|
||||
$config['show_modname'] = false;
|
||||
|
||||
@ -1410,7 +1421,7 @@
|
||||
$config['mod']['view_banlist'] = MOD;
|
||||
// View the username of the mod who made a ban
|
||||
$config['mod']['view_banstaff'] = MOD;
|
||||
// If the moderator doesn't fit the $config['mod']['view_banstaff''] (previous) permission, show him just
|
||||
// If the moderator doesn't fit the $config['mod']['view_banstaff'] (previous) permission, show him just
|
||||
// a "?" instead. Otherwise, it will be "Mod" or "Admin".
|
||||
$config['mod']['view_banquestionmark'] = false;
|
||||
// Show expired bans in the ban list (they are kept in cache until the culprit returns)
|
||||
|
@ -495,7 +495,15 @@ function mod_new_board() {
|
||||
if (openBoard($_POST['uri'])) {
|
||||
error(sprintf($config['error']['boardexists'], $board['url']));
|
||||
}
|
||||
|
||||
foreach ($config['banned_boards'] as $i => $w) {
|
||||
if ($w[0] !== '/') {
|
||||
if (strpos($_POST['uri'],$w) !== false)
|
||||
error(_("Cannot create board with banned word $w"));
|
||||
} else {
|
||||
if (preg_match($w,$_POST['uri']))
|
||||
error(_("Cannot create board matching banned pattern $w"));
|
||||
}
|
||||
}
|
||||
$query = prepare('INSERT INTO ``boards`` (``uri``, ``title``, ``subtitle``) VALUES (:uri, :title, :subtitle)');
|
||||
$query->bindValue(':uri', $_POST['uri']);
|
||||
$query->bindValue(':title', $_POST['title']);
|
||||
|
Loading…
Reference in New Issue
Block a user