mirror of
https://github.com/the-djmaze/snappymail.git
synced 2026-09-08 17:07:03 +03:00
Resolve #1018
This commit is contained in:
parent
dc06502744
commit
b85ed63ff6
1 changed files with 11 additions and 9 deletions
|
|
@ -61,6 +61,8 @@ abstract class Service
|
||||||
} else {
|
} else {
|
||||||
\ob_start('ob_gzhandler');
|
\ob_start('ob_gzhandler');
|
||||||
}
|
}
|
||||||
|
} else {
|
||||||
|
\ob_start();
|
||||||
}
|
}
|
||||||
|
|
||||||
$sQuery = \trim($_SERVER['QUERY_STRING'] ?? '');
|
$sQuery = \trim($_SERVER['QUERY_STRING'] ?? '');
|
||||||
|
|
@ -110,7 +112,6 @@ abstract class Service
|
||||||
}
|
}
|
||||||
|
|
||||||
$bIndex = true;
|
$bIndex = true;
|
||||||
$sResult = '';
|
|
||||||
if (\count($aPaths) && !empty($aPaths[0]) && 'index' !== \strtolower($aPaths[0])) {
|
if (\count($aPaths) && !empty($aPaths[0]) && 'index' !== \strtolower($aPaths[0])) {
|
||||||
if ('mailto' !== \strtolower($aPaths[0]) && !\SnappyMail\HTTP\SecFetch::matchAnyRule($oConfig->Get('security', 'secfetch_allow', ''))) {
|
if ('mailto' !== \strtolower($aPaths[0]) && !\SnappyMail\HTTP\SecFetch::matchAnyRule($oConfig->Get('security', 'secfetch_allow', ''))) {
|
||||||
\MailSo\Base\Http::StatusHeader(403);
|
\MailSo\Base\Http::StatusHeader(403);
|
||||||
|
|
@ -123,15 +124,15 @@ abstract class Service
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
$bIndex = false;
|
|
||||||
$sMethodName = 'Service'.\preg_replace('/@.+$/', '', $aPaths[0]);
|
$sMethodName = 'Service'.\preg_replace('/@.+$/', '', $aPaths[0]);
|
||||||
$sMethodExtra = \strpos($aPaths[0], '@') ? \preg_replace('/^[^@]+@/', '', $aPaths[0]) : '';
|
$sMethodExtra = \strpos($aPaths[0], '@') ? \preg_replace('/^[^@]+@/', '', $aPaths[0]) : '';
|
||||||
|
|
||||||
if (\method_exists($oServiceActions, $sMethodName) && \is_callable(array($oServiceActions, $sMethodName))) {
|
if (\method_exists($oServiceActions, $sMethodName) && \is_callable(array($oServiceActions, $sMethodName))) {
|
||||||
|
$bIndex = false;
|
||||||
$oServiceActions->SetQuery($sQuery)->SetPaths($aPaths);
|
$oServiceActions->SetQuery($sQuery)->SetPaths($aPaths);
|
||||||
$sResult = $oServiceActions->{$sMethodName}($sMethodExtra);
|
echo $oServiceActions->{$sMethodName}($sMethodExtra);
|
||||||
} else if (!$oActions->Plugins()->RunAdditionalPart($aPaths[0], $aPaths)) {
|
} else if ($oActions->Plugins()->RunAdditionalPart($aPaths[0], $aPaths)) {
|
||||||
$bIndex = true;
|
$bIndex = false;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -196,6 +197,8 @@ abstract class Service
|
||||||
$oActions->verifyCacheByKey($sCacheFileName);
|
$oActions->verifyCacheByKey($sCacheFileName);
|
||||||
if ($oConfig->Get('cache', 'system_data', true)) {
|
if ($oConfig->Get('cache', 'system_data', true)) {
|
||||||
$sResult = $oActions->Cacher()->Get($sCacheFileName);
|
$sResult = $oActions->Cacher()->Get($sCacheFileName);
|
||||||
|
} else {
|
||||||
|
$sResult = '';
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($sResult) {
|
if ($sResult) {
|
||||||
|
|
@ -232,14 +235,13 @@ abstract class Service
|
||||||
static::setCSP(null, $sScriptHash);
|
static::setCSP(null, $sScriptHash);
|
||||||
*/
|
*/
|
||||||
$oActions->cacheByKey($sCacheFileName);
|
$oActions->cacheByKey($sCacheFileName);
|
||||||
|
|
||||||
|
echo $sResult;
|
||||||
|
unset($sResult);
|
||||||
} else if (!\headers_sent()) {
|
} else if (!\headers_sent()) {
|
||||||
\header('X-XSS-Protection: 1; mode=block');
|
\header('X-XSS-Protection: 1; mode=block');
|
||||||
}
|
}
|
||||||
|
|
||||||
// Output result
|
|
||||||
echo $sResult;
|
|
||||||
unset($sResult);
|
|
||||||
|
|
||||||
$oActions->BootEnd();
|
$oActions->BootEnd();
|
||||||
|
|
||||||
return true;
|
return true;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue