Merge pull request 'Deiteiincludes ($pfad) per whitelist prüfen' (#53) from AllowistDateiincludes into dev
Reviewed-on: #53
This commit was merged in pull request #53.
This commit is contained in:
@@ -2,52 +2,10 @@
|
|||||||
if (session_status() === PHP_SESSION_NONE) {
|
if (session_status() === PHP_SESSION_NONE) {
|
||||||
session_start();
|
session_start();
|
||||||
}
|
}
|
||||||
ob_start();
|
include_once "php/controller/index-controller.php";
|
||||||
include_once("php/controller/index.php");
|
|
||||||
|
|
||||||
$pfad = $_GET["pfad"] ?? "home";
|
|
||||||
|
|
||||||
/*
|
|
||||||
Controller für Aktionen werden vor der HTML-Ausgabe geladen,
|
|
||||||
damit Weiterleitungen mit header() funktionieren.
|
|
||||||
*/
|
|
||||||
if ($pfad === "login") {
|
|
||||||
include_once "php/controller/login-controller.php";
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($pfad === "register") {
|
|
||||||
include_once "php/controller/register-controller.php";
|
|
||||||
}
|
|
||||||
if ($pfad === "password-forgotten") {
|
|
||||||
include_once "php/controller/password-forgotten-controller.php";
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($pfad === "confirm-register") {
|
|
||||||
include_once "php/controller/confirm-register-controller.php";
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($pfad === "confirm-password") {
|
|
||||||
include_once "php/controller/confirm-password-controller.php";
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($pfad === "logout") {
|
|
||||||
include_once "php/controller/logout-controller.php";
|
|
||||||
exit();
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($pfad === "deleteAccount") {
|
|
||||||
include_once "php/controller/deleteAccount-controller.php";
|
|
||||||
exit();
|
|
||||||
}
|
|
||||||
?>
|
?>
|
||||||
|
|
||||||
<!--
|
|
||||||
Seite: Index der Lernplattform
|
|
||||||
Funktion: Webseitengerüst, Anzeigen von Content
|
|
||||||
-->
|
|
||||||
<!DOCTYPE html>
|
<!DOCTYPE html>
|
||||||
<html lang="de">
|
<html lang="de">
|
||||||
|
|
||||||
<head>
|
<head>
|
||||||
<meta charset="utf-8">
|
<meta charset="utf-8">
|
||||||
<meta name="description" content="EduForge">
|
<meta name="description" content="EduForge">
|
||||||
@@ -73,17 +31,13 @@ if ($pfad === "deleteAccount") {
|
|||||||
|
|
||||||
<title>EduForge</title>
|
<title>EduForge</title>
|
||||||
</head>
|
</head>
|
||||||
|
|
||||||
<body>
|
<body>
|
||||||
|
|
||||||
<?php
|
<?php
|
||||||
include_once 'includes/navbar.php';
|
include_once 'includes/navbar.php';
|
||||||
|
|
||||||
/*
|
// Dynamischer Inhalt
|
||||||
Dynamischer Inhalt:
|
if (isset($pfad) && $pfad !== "404" && file_exists('content/' . $pfad . '.php')) {
|
||||||
Je nach pfad-Parameter wird die passende Datei aus content geladen.
|
|
||||||
*/
|
|
||||||
if (file_exists('content/' . $pfad . '.php')) {
|
|
||||||
include_once 'content/' . $pfad . '.php';
|
include_once 'content/' . $pfad . '.php';
|
||||||
} else {
|
} else {
|
||||||
include_once 'content/404.php';
|
include_once 'content/404.php';
|
||||||
@@ -94,7 +48,3 @@ if ($pfad === "deleteAccount") {
|
|||||||
|
|
||||||
</body>
|
</body>
|
||||||
</html>
|
</html>
|
||||||
|
|
||||||
<?php
|
|
||||||
ob_end_flush();
|
|
||||||
?>
|
|
||||||
@@ -1,3 +1,35 @@
|
|||||||
<?php
|
<?php
|
||||||
|
// Standardpfad
|
||||||
|
$pfad = $_GET["pfad"] ?? "home";
|
||||||
|
|
||||||
?>
|
if ($pfad === "logout") {
|
||||||
|
include_once "php/controller/logout-controller.php";
|
||||||
|
exit();
|
||||||
|
} elseif ($pfad === "deleteAccount") {
|
||||||
|
include_once "php/controller/deleteAccount-controller.php";
|
||||||
|
exit();
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($pfad === "login") {
|
||||||
|
include_once "php/controller/login-controller.php";
|
||||||
|
} elseif ($pfad === "register") {
|
||||||
|
include_once "php/controller/register-controller.php";
|
||||||
|
} elseif ($pfad === "password-forgotten") {
|
||||||
|
include_once "php/controller/password-forgotten-controller.php";
|
||||||
|
} elseif ($pfad === "confirm-register") {
|
||||||
|
include_once "php/controller/confirm-register-controller.php";
|
||||||
|
} elseif ($pfad === "confirm-password") {
|
||||||
|
include_once "php/controller/confirm-password-controller.php";
|
||||||
|
}
|
||||||
|
|
||||||
|
// Whitelist
|
||||||
|
$erlaubte_content_seiten = [
|
||||||
|
"accessibility", "confirm-password", "confirm-register", "createArticle",
|
||||||
|
"datenschutz", "home", "impressum", "login", "nutzungsbedingungen",
|
||||||
|
"password-forgotten", "profile", "register", "search-results",
|
||||||
|
"show-mail", "showArticle", "showCategory", "updateArticle"
|
||||||
|
];
|
||||||
|
|
||||||
|
if (!in_array($pfad, $erlaubte_content_seiten)) {
|
||||||
|
$pfad = "404";
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user