diff options
author | cinap_lenrek <cinap_lenrek@felloff.net> | 2015-03-14 01:09:37 +0100 |
---|---|---|
committer | cinap_lenrek <cinap_lenrek@felloff.net> | 2015-03-14 01:09:37 +0100 |
commit | 2443d46a9ead610cdeebdc389f7b05356216d93e (patch) | |
tree | 4ff61fe4e6ffd5de1e49abc3becdf9f1e22e8f57 /sys/src/cmd/webfs/fs.c | |
parent | 8ef66ca21218af00181bf78f37a5ede0238a7fa1 (diff) |
webfs: do not send credentials in automatic referer url
Diffstat (limited to 'sys/src/cmd/webfs/fs.c')
-rw-r--r-- | sys/src/cmd/webfs/fs.c | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/sys/src/cmd/webfs/fs.c b/sys/src/cmd/webfs/fs.c index 117bdc0b4..981884417 100644 --- a/sys/src/cmd/webfs/fs.c +++ b/sys/src/cmd/webfs/fs.c @@ -421,6 +421,11 @@ fsopen(Req *r) u->host = smprint("%H", r); free(r); } + + /* do not send credentials */ + free(u->user); u->user = nil; + free(u->pass); u->pass = nil; + if(r = smprint("%U", u)){ cl->hdr = addkey(cl->hdr, "Referer", r); free(r); |