Fix for bug 28235: IE6 looks for the file extension in the query string
[lhc/web/wiklou.git] / load.php
1 <?php
2 /**
3 * This file is the entry point for the resource loader.
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
9 *
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License along
16 * with this program; if not, write to the Free Software Foundation, Inc.,
17 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
18 * http://www.gnu.org/copyleft/gpl.html
19 *
20 * @file
21 * @author Roan Kattouw
22 * @author Trevor Parscal
23 *
24 */
25
26 require ( dirname( __FILE__ ) . '/includes/WebStart.php' );
27 wfProfileIn( 'load.php' );
28
29 // URL safety checks
30 //
31 // See RawPage.php for details; summary is that MSIE can override the
32 // Content-Type if it sees a recognized extension on the URL, such as
33 // might be appended via PATH_INFO after 'load.php'.
34 //
35 // Some resources can contain HTML-like strings (e.g. in messages)
36 // which will end up triggering HTML detection and execution.
37 //
38 if ( $wgRequest->isPathInfoBad() ) {
39 wfHttpError( 403, 'Forbidden',
40 'Invalid file extension found in PATH_INFO or QUERY_STRING.' );
41 return;
42 }
43
44 // Respond to resource loading request
45 $resourceLoader = new ResourceLoader();
46 $resourceLoader->respond( new ResourceLoaderContext( $resourceLoader, $wgRequest ) );
47
48 wfProfileOut( 'load.php' );
49 wfLogProfilingData();
50
51 // Shut down the database
52 wfGetLBFactory()->shutdown();