Disallow loading JS/CSS/Json subpages from unregistered users and log
authorBrian Wolff <bawolff+wn@gmail.com>
Tue, 15 May 2018 00:34:14 +0000 (00:34 +0000)
committerBrian Wolff <bawolff+wn@gmail.com>
Tue, 15 May 2018 00:49:35 +0000 (00:49 +0000)
commit0be838ed6a2954b98a6b66ba7bacbf91fcb06579
tree601a8b7b46899f49e28313cff7fd27bbdf38b64c
parent10fcb52726982f7d51cac4d43689daa607147fc6
Disallow loading JS/CSS/Json subpages from unregistered users and log

Loading JS from an unregistered user's JS subpage is a severe
security risk as someone could potentially register that account
and then modify the JS.

Bug: T194204
Change-Id: I741736e12b0ed49e95f22c869a2b53e2c97b31f0
includes/actions/RawAction.php
languages/i18n/en.json
languages/i18n/qqq.json