[Mapbender-commits] r9333 - trunk/mapbender/http/print/classes
svn_mapbender at osgeo.org
svn_mapbender at osgeo.org
Wed Dec 9 01:00:16 PST 2015
Author: pschmidt
Date: 2015-12-09 01:00:15 -0800 (Wed, 09 Dec 2015)
New Revision: 9333
Modified:
trunk/mapbender/http/print/classes/mbSvgDecorator.php
Log:
check if GET parameter "svg_extent" is valid
Modified: trunk/mapbender/http/print/classes/mbSvgDecorator.php
===================================================================
--- trunk/mapbender/http/print/classes/mbSvgDecorator.php 2015-12-08 15:31:27 UTC (rev 9332)
+++ trunk/mapbender/http/print/classes/mbSvgDecorator.php 2015-12-09 09:00:15 UTC (rev 9333)
@@ -36,7 +36,8 @@
global $yAxisOrientation;
$yAxisOrientation = 1;
$doc = new \DOMDocument();
- if (isset($_REQUEST[$this->svgParam]) && $_REQUEST[$this->svgParam] != "" && @$doc->loadXML($_REQUEST[$this->svgParam])) {
+ if (isset($_REQUEST["svg_extent"]) && $_REQUEST["svg_extent"] !== "" && count(explode(',', $_REQUEST["svg_extent"])) === 4 &&
+ isset($_REQUEST[$this->svgParam]) && $_REQUEST[$this->svgParam] !== "" && @$doc->loadXML($_REQUEST[$this->svgParam])) {
$e = new mb_notice("mbSvgDecorator: svg: " . $_REQUEST[$this->svgParam]);
} else {
return "No svg found.";
More information about the Mapbender_commits
mailing list