Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions src/Ui/UiRequest.py
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,9 @@ def isWebSocketRequest(self):
def isAjaxRequest(self):
return self.env.get("HTTP_X_REQUESTED_WITH") == "XMLHttpRequest"

def isNormalMethods(self):
return self.env['REQUEST_METHOD'] in ['GET', 'HEAD', 'OPTIONS']

# Get mime by filename
def getContentType(self, file_name):
content_type = mimetypes.guess_type(file_name)[0]
Expand Down Expand Up @@ -190,6 +193,9 @@ def actionIndex(self):

# Render a file from media with iframe site wrapper
def actionWrapper(self, path, extra_headers=None):
if not self.isNormalMethods():
return self.error403("Method not allowed to request wrapper!")

if not extra_headers:
extra_headers = []

Expand Down Expand Up @@ -339,6 +345,9 @@ def parsePath(self, path):

# Serve a media for site
def actionSiteMedia(self, path, header_length=True):
if not self.isNormalMethods():
return self.error403("Method not allowed to request site media!")

path_parts = self.parsePath(path)

# Check wrapper nonce
Expand Down