Fixing @ in POST parameters which could cause sending file from filesystem as POST data.
This commit is contained in:
parent
d9082a3a71
commit
b712307782
|
@ -79,6 +79,11 @@ class AbstractApi
|
||||||
*/
|
*/
|
||||||
public function sendPostRequest($path, array $parameters = [])
|
public function sendPostRequest($path, array $parameters = [])
|
||||||
{
|
{
|
||||||
|
// Cleaning POST parameters from potential @file injections
|
||||||
|
array_walk($parameters, function (string &$value, string $key) {
|
||||||
|
str_replace('@', '', $value);
|
||||||
|
});
|
||||||
|
|
||||||
/** @var GuzzleRequest $request */
|
/** @var GuzzleRequest $request */
|
||||||
$request = $this->client->post($path, null, $parameters);
|
$request = $this->client->post($path, null, $parameters);
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue