Pārlūkot izejas kodu

Fix for downloading backup of other users

Anton Reutov 4 gadi atpakaļ
vecāks
revīzija
1c801b2d60
1 mainītis faili ar 7 papildinājumiem un 0 dzēšanām
  1. 7 0
      web/download/backup/index.php

+ 7 - 0
web/download/backup/index.php

@@ -3,6 +3,13 @@
 error_reporting(NULL);
 session_start();
 include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
+
+// Check token
+if ((!isset($_GET['token'])) || ($_SESSION['token'] != $_GET['token'])) {
+    header('Location: /login/');
+    exit();
+}
+
 $backup = basename($_GET['backup']);
 
 // Check if the backup exists