From 85313d6f550a93b5757c8876ab5733c3abea9246 Mon Sep 17 00:00:00 2001 From: Gina Haeussge Date: Sat, 11 Oct 2008 14:14:50 +0200 Subject: Do not allow values for $conf[start] which contain namespaces darcs-hash:20081011121450-2b4f5-1e3139cc20cea62247be931ebc2749b8fb02c002.gz --- lib/plugins/config/settings/config.metadata.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'lib/plugins/config') diff --git a/lib/plugins/config/settings/config.metadata.php b/lib/plugins/config/settings/config.metadata.php index ee558b767..c087cd767 100644 --- a/lib/plugins/config/settings/config.metadata.php +++ b/lib/plugins/config/settings/config.metadata.php @@ -81,7 +81,7 @@ $file['protected'] = "DOKU_CONF.'local.protected.php'"; // optional $meta['_basic'] = array('fieldset'); $meta['title'] = array('string'); -$meta['start'] = array('string'); +$meta['start'] = array('string','_pattern' => '!^[^:;/]+$!'); // don't accept namespaces $meta['lang'] = array('dirchoice','_dir' => DOKU_INC.'inc/lang/'); $meta['template'] = array('dirchoice','_dir' => DOKU_INC.'lib/tpl/','_pattern' => '/^[\w-]+$/'); $meta['savedir'] = array('savedir'); -- cgit v1.2.3