Deiteiincludes ($pfad) per whitelist prüfen #53

Merged
niklas.ortmann merged 10 commits from AllowistDateiincludes into dev 2026-07-18 18:31:56 +02:00
Showing only changes of commit 4dadfb8863 - Show all commits
+3 -51
View File
@@ -2,52 +2,12 @@
if (session_status() === PHP_SESSION_NONE) {
session_start();
}
ob_start();
include_once("php/controller/index.php");
$pfad = $_GET["pfad"] ?? "home";
include_once("php/controller/index-controller.php");
/*
Controller für Aktionen werden vor der HTML-Ausgabe geladen,
damit Weiterleitungen mit header() funktionieren.
*/
if ($pfad === "login") {
include_once "php/controller/login-controller.php";
}
if ($pfad === "register") {
include_once "php/controller/register-controller.php";
}
if ($pfad === "password-forgotten") {
include_once "php/controller/password-forgotten-controller.php";
}
if ($pfad === "confirm-register") {
include_once "php/controller/confirm-register-controller.php";
}
if ($pfad === "confirm-password") {
include_once "php/controller/confirm-password-controller.php";
}
if ($pfad === "logout") {
include_once "php/controller/logout-controller.php";
exit();
}
if ($pfad === "deleteAccount") {
include_once "php/controller/deleteAccount-controller.php";
exit();
}
?>
<!--
Seite: Index der Lernplattform
Funktion: Webseitengerüst, Anzeigen von Content
-->
<!DOCTYPE html>
<html lang="de">
<head>
<meta charset="utf-8">
<meta name="description" content="EduForge">
@@ -73,17 +33,13 @@ if ($pfad === "deleteAccount") {
<title>EduForge</title>
</head>
<body>
<?php
include_once 'includes/navbar.php';
/*
Dynamischer Inhalt:
Je nach pfad-Parameter wird die passende Datei aus content geladen.
*/
if (file_exists('content/' . $pfad . '.php')) {
// Dynamischer Inhalt (Absolut sicher durch die obige Prüfung)
if (isset($pfad) && $pfad !== "404" && file_exists('content/' . $pfad . '.php')) {
include_once 'content/' . $pfad . '.php';
} else {
include_once 'content/404.php';
@@ -94,7 +50,3 @@ if ($pfad === "deleteAccount") {
</body>
</html>
<?php
ob_end_flush();
?>