From 65c24af9d5aea4cb763bf54333a0d7de02f935dd Mon Sep 17 00:00:00 2001 From: dpeca Date: Wed, 11 Sep 2019 23:48:33 +0200 Subject: [PATCH] Update secure_login.php --- web/inc/secure_login.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/web/inc/secure_login.php b/web/inc/secure_login.php index 46393d79..7ab32ae0 100644 --- a/web/inc/secure_login.php +++ b/web/inc/secure_login.php @@ -8,6 +8,8 @@ if ($_SERVER['SCRIPT_FILENAME']=='/usr/local/vesta/web/reset/mail/set-ar.php') $ if ($_SERVER['SCRIPT_FILENAME']=='/usr/local/vesta/web//reset/mail/set-ar.php') $skip_login_url_check=1; if ($_SERVER['SCRIPT_FILENAME']=='/usr/local/vesta/web/reset/mail/get-ar.php') $skip_login_url_check=1; if ($_SERVER['SCRIPT_FILENAME']=='/usr/local/vesta/web//reset/mail/get-ar.php') $skip_login_url_check=1; +if (substr($_SERVER['SCRIPT_FILENAME'], 0, 28)=='/usr/local/vesta/web/custom/') $login_url_skip=1; // custom scripts like git webhooks +if (substr($_SERVER['SCRIPT_FILENAME'], 0, 29)=='/usr/local/vesta/web//custom/') $login_url_skip=1; if (substr($_SERVER['SCRIPT_FILENAME'], 0, 21)=='/usr/local/vesta/bin/') $skip_login_url_check=1; // allow executing v-* PHP scripts from bash