aboutsummaryrefslogtreecommitdiffstats
path: root/Zotlabs/Module/Nojs.php
diff options
context:
space:
mode:
authorzotlabs <mike@macgirvin.com>2018-07-18 17:05:38 -0700
committerzotlabs <mike@macgirvin.com>2018-07-18 17:05:38 -0700
commit5ce50d0a2e15ae66765a68ba2785a87ecda57f6a (patch)
tree52c5b31392f6ea036420fc1014e4366075710e99 /Zotlabs/Module/Nojs.php
parent744d548380fb3df074ce8abb78977ddc344744db (diff)
downloadvolse-hubzilla-5ce50d0a2e15ae66765a68ba2785a87ecda57f6a.tar.gz
volse-hubzilla-5ce50d0a2e15ae66765a68ba2785a87ecda57f6a.tar.bz2
volse-hubzilla-5ce50d0a2e15ae66765a68ba2785a87ecda57f6a.zip
mangled urls on redirects
Diffstat (limited to 'Zotlabs/Module/Nojs.php')
-rw-r--r--Zotlabs/Module/Nojs.php4
1 files changed, 2 insertions, 2 deletions
diff --git a/Zotlabs/Module/Nojs.php b/Zotlabs/Module/Nojs.php
index 6fd6d8106..5f3d80ecd 100644
--- a/Zotlabs/Module/Nojs.php
+++ b/Zotlabs/Module/Nojs.php
@@ -7,8 +7,8 @@ class Nojs extends \Zotlabs\Web\Controller {
function init() {
$n = ((argc() > 1) ? intval(argv(1)) : 1);
setcookie('jsdisabled', $n, 0, '/');
- $p = $_GET['redir'];
- $hasq = strpos($p,'?');
+ $p = hex2bin($_GET['redir']);
+ $hasq = strpbrk($p,'?&');
goaway(z_root() . (($p) ? '/' . $p : '') . (($hasq) ? '' : '?f=' ) . '&jsdisabled=' . $n);
}