Mercurial > hg > isophonics-drupal-site
view core/modules/toolbar/src/PageCache/AllowToolbarPath.php @ 13:5fb285c0d0e3
Update Drupal core to 8.4.7 via Composer. Security update; I *think* we've
been lucky to get away with this so far, as we don't support self-registration
which seems to be used by the so-called "drupalgeddon 2" attack that 8.4.5
was vulnerable to.
author | Chris Cannam |
---|---|
date | Mon, 23 Apr 2018 09:33:26 +0100 |
parents | 4c8ae668cc8c |
children |
line wrap: on
line source
<?php namespace Drupal\toolbar\PageCache; use Drupal\Core\PageCache\RequestPolicyInterface; use Symfony\Component\HttpFoundation\Request; /** * Cache policy for the toolbar page cache service. * * This policy allows caching of requests directed to /toolbar/subtrees/{hash} * even for authenticated users. */ class AllowToolbarPath implements RequestPolicyInterface { /** * {@inheritdoc} */ public function check(Request $request) { // Note that this regular expression matches the end of pathinfo in order to // support multilingual sites using path prefixes. if (preg_match('#/toolbar/subtrees/[^/]+(/[^/]+)?$#', $request->getPathInfo())) { return static::ALLOW; } } }