From: Felix Dörre Date: Thu, 24 Jul 2014 22:49:15 +0000 (+0200) Subject: Enforce POST requests to only contain POST data. X-Git-Url: https://code.wpia.club/?p=gigi.git;a=commitdiff_plain;h=6b985b637949909402c2e7be5e682b33d5e6abcd Enforce POST requests to only contain POST data. --- diff --git a/src/org/cacert/gigi/Gigi.java b/src/org/cacert/gigi/Gigi.java index d584cd09..9d1bb1b9 100644 --- a/src/org/cacert/gigi/Gigi.java +++ b/src/org/cacert/gigi/Gigi.java @@ -109,6 +109,9 @@ public class Gigi extends HttpServlet { public void output(PrintWriter out, Language l, Map vars) { try { if (req.getMethod().equals("POST")) { + if (req.getQueryString() != null) { + return; + } p.doPost(req, resp); } else { p.doGet(req, resp);