Closing tags at the end of file are not mandatory. It is often suggested to omit to closing tags at the end of file to prevent unwanted effects as PHP will start output buffering if there is any character after closing tag. Reference: http://php.net/manual/en/language.basic-syntax.phptags.php Signed-off-by: Rahul Kadyan <hi@znck.me>
38 lines
1.1 KiB
PHP
38 lines
1.1 KiB
PHP
<?php
|
|
/* vim: set expandtab sw=4 ts=4 sts=4: */
|
|
/**
|
|
* URL redirector to avoid leaking Referer with some sensitive information.
|
|
*
|
|
* @package PhpMyAdmin
|
|
*/
|
|
|
|
/**
|
|
* Gets core libraries and defines some variables
|
|
*/
|
|
define('PMA_MINIMUM_COMMON', true);
|
|
require_once './libraries/common.inc.php';
|
|
/**
|
|
* JavaScript escaping.
|
|
*/
|
|
require_once './libraries/js_escape.lib.php';
|
|
|
|
if (! PMA_isValid($_GET['url'])
|
|
|| ! preg_match('/^https?:\/\/[^\n\r]*$/', $_GET['url'])
|
|
|| ! PMA_isAllowedDomain($_GET['url'])
|
|
) {
|
|
header('Location: ' . $cfg['PmaAbsoluteUri']);
|
|
} else {
|
|
// JavaScript redirection is necessary. Because if header() is used
|
|
// then web browser sometimes does not change the HTTP_REFERER
|
|
// field and so with old URL as Referer, token also goes to
|
|
// external site.
|
|
echo "<script type='text/javascript'>
|
|
window.onload=function(){
|
|
window.location='" . PMA_escapeJsString($_GET['url']) . "';
|
|
}
|
|
</script>";
|
|
// Display redirecting msg on screen.
|
|
printf(__('Taking you to %s.'), htmlspecialchars($_GET['url']));
|
|
}
|
|
die();
|