Merge branch 'MDL-48929-master' of git://github.com/FMCorz/moodle

This commit is contained in:
Andrew Nicols 2015-02-03 13:55:32 +08:00
commit 48bac91be8

View file

@ -575,7 +575,7 @@ class repository_filesystem extends repository {
$fullrelativefilepath = realpath($this->get_rootpath().$basepath.$relativepath);
// Sanity check to make sure this path is inside this repository and the file exists.
if (strpos($fullrelativefilepath, $this->get_rootpath()) === 0 && file_exists($fullrelativefilepath)) {
if (strpos($fullrelativefilepath, realpath($this->get_rootpath())) === 0 && file_exists($fullrelativefilepath)) {
send_file($fullrelativefilepath, basename($relativepath), null, 0);
}
}
@ -665,4 +665,4 @@ function repository_filesystem_cron() {
$instances[$itemid]->remove_obsolete_thumbnails($files);
}
}
}
}