Page MenuHomeDevCentral

Don't call get_url from templates
ClosedPublic

Authored by dereckson on Sun, Oct 19, 23:19.

Details

Summary

To avoid arbitrary execution of PHP code inside Smarty,
move the responsibility to call get_url() from the template
to the relevant controller code.

Diff Detail

Repository
rOBSIDIAN Obsidian Workspaces
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

dereckson created this revision.
dereckson added inline comments.
workspaces/src/controllers/errorpage.php
61 ↗(On Diff #9796)

Already defined line 56.

Use already defined URL_HOME in 404

This revision is now accepted and ready to land.Sun, Oct 19, 23:26
This revision was automatically updated to reflect the committed changes.