Protect users from attacks against their browsers via malicious script-containing...
authorTim Starling <tstarling@users.mediawiki.org>
Tue, 18 Nov 2008 05:57:08 +0000 (05:57 +0000)
committerTim Starling <tstarling@users.mediawiki.org>
Tue, 18 Nov 2008 05:57:08 +0000 (05:57 +0000)
commit6b5143fd2c633fe97a09ad3a36455e3f271b0200
treebffe3ad2a3826435871c1b527751e47008b08ffc
parent829f1142b0e834979b3a73a3a1aa6a58347cacf4
Protect users from attacks against their browsers via malicious script-containing uploads, by:
1) Requiring a session token before streaming files out via Special:Undelete
2) Restricting img_auth.php to private wikis only (its intended use case)
img_auth.php
includes/specials/SpecialUndelete.php
languages/messages/MessagesEn.php