From: Andrew Dolgov Date: Fri, 10 Feb 2017 19:02:30 +0000 (+0300) Subject: af_zz_imgproxy: redirect to caller url unless called in user context X-Git-Tag: 17.4~45 X-Git-Url: https://git.wh0rd.org/?a=commitdiff_plain;h=2187322caee25756d28983f069e291612023c6dc;p=tt-rss.git af_zz_imgproxy: redirect to caller url unless called in user context --- diff --git a/plugins/af_zz_imgproxy/init.php b/plugins/af_zz_imgproxy/init.php index 5d9a96ac..6d7954c3 100644 --- a/plugins/af_zz_imgproxy/init.php +++ b/plugins/af_zz_imgproxy/init.php @@ -35,6 +35,12 @@ class Af_Zz_ImgProxy extends Plugin { $url = rewrite_relative_url(SELF_URL_PATH, $_REQUEST["url"]); $kind = (int) $_REQUEST["kind"]; // 1 = video + // called without user context, let's just redirect to original URL + if (!$_SESSION["uid"]) { + header("Location: $url"); + return; + } + $extension = $kind == 1 ? '.mp4' : '.png'; $local_filename = CACHE_DIR . "/images/" . sha1($url) . $extension;