From 29176a0753c38260f0ded0e7f717e9d29f09465b Mon Sep 17 00:00:00 2001 From: Daniel Seifert Date: Wed, 4 Dec 2024 15:23:02 +0100 Subject: [PATCH] set appropriate header in case of unauthorised access --- assets/out/fileman/php/security.inc.php | 32 ++++++++++--------------- 1 file changed, 12 insertions(+), 20 deletions(-) diff --git a/assets/out/fileman/php/security.inc.php b/assets/out/fileman/php/security.inc.php index 5db629b..d5db394 100755 --- a/assets/out/fileman/php/security.inc.php +++ b/assets/out/fileman/php/security.inc.php @@ -1,29 +1,21 @@ + * @link https://www.oxidmodule.com + */ - This program is free software: you can redistribute it and/or modify - it under the terms of the GNU General Public License as published by - the Free Software Foundation, either version 3 of the License. - - This program is distributed in the hope that it will be useful, - but WITHOUT ANY WARRANTY; without even the implied warranty of - MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the - GNU General Public License for more details. - - You should have received a copy of the GNU General Public License - along with this program. If not, see . - - Contact: Lyubomir Arsov, liubo (at) web-lobby.com -*/ function checkAccess(string $action): void { unset($action); if ($_COOKIE['filemanagerkey'] !== md5_file(__DIR__."/../../../../../../../source/config.inc.php")) { - die('nice try, noob.'); + header("HTTP/1.1 401 Unauthorized"); + die(); } }