2
0
Эх сурвалжийг харах

[Web] deny api calls from sogo

FreddleSpl0it 1 жил өмнө
parent
commit
00d4b32a1b

+ 8 - 0
data/web/json_api.php

@@ -47,6 +47,14 @@ function api_log($_data) {
   }
   }
 }
 }
 
 
+// deny requests from /SOGo locations
+if (isset($_SERVER['HTTP_REFERER'])) {
+  if (strpos(strtolower($_SERVER['HTTP_REFERER']), '/sogo') !== false) {
+    header('HTTP/1.1 403 Forbidden');
+    exit;
+  }
+}
+
 if (isset($_GET['query'])) {
 if (isset($_GET['query'])) {
 
 
   $query = explode('/', $_GET['query']);
   $query = explode('/', $_GET['query']);