diff options
author | Simon Rettberg | 2019-02-12 14:55:49 +0100 |
---|---|---|
committer | Simon Rettberg | 2019-02-12 14:55:49 +0100 |
commit | ec4ac82adaabe55cb9c3c40fad66d3451cb5f4d9 (patch) | |
tree | 0134ad4e33aa259250fb46a82e7da44b091db88e /inc/dictionary.inc.php | |
parent | [serversetup*] PXELinux and iPXE side-by-side (diff) | |
parent | [inc/Dictionary] Teh evil unvalidated redirects must die! (diff) | |
download | slx-admin-ipxe.tar.gz slx-admin-ipxe.tar.xz slx-admin-ipxe.zip |
Merge branch 'master' into ipxeipxe
Diffstat (limited to 'inc/dictionary.inc.php')
-rw-r--r-- | inc/dictionary.inc.php | 11 |
1 files changed, 8 insertions, 3 deletions
diff --git a/inc/dictionary.inc.php b/inc/dictionary.inc.php index fcbfdfb8..935d1f4e 100644 --- a/inc/dictionary.inc.php +++ b/inc/dictionary.inc.php @@ -30,10 +30,15 @@ class Dictionary if ($lang !== false && in_array($lang, self::$languages)) { setcookie('lang', $lang, time() + 60 * 60 * 24 * 30 * 12); $url = Request::get('url'); - if ($url === false && isset($_SERVER['HTTP_REFERER'])) + if ($url === false && isset($_SERVER['HTTP_REFERER'])) { $url = $_SERVER['HTTP_REFERER']; - if ($url === false) - $url = '?do=Main'; + } + $parts = parse_url($url); + if ($url === false || $parts === false || empty($parts['query'])) { + $url = '?do=main'; + } else { + $url = '?' . $parts['query']; + } Util::redirect($url); } |