summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authordsnopek2018-02-22 16:31:39 (GMT)
committerDavid Snopek2018-02-22 16:31:39 (GMT)
commit6d7a0890e603351d66cc9c9754bd0c81ee0476e5 (patch)
treeb01841508f81dcb00280fd58a8a39d3f58f34496
parentac652689712d9a56a62d25587b6ffd6b5884e392 (diff)
Issue #2946582 by dsnopek: [core] Add D6LTS patch for SA-CORE-2018-001 (fix IMCE issue)
-rw-r--r--common/core/SA-CORE-2018-001.patch4
1 files changed, 2 insertions, 2 deletions
diff --git a/common/core/SA-CORE-2018-001.patch b/common/core/SA-CORE-2018-001.patch
index 77df8b0..741f3eb 100644
--- a/common/core/SA-CORE-2018-001.patch
+++ b/common/core/SA-CORE-2018-001.patch
@@ -12,7 +12,7 @@ index 9a28c06..a5c362d 100644
// May need language dependent rewriting if language.inc is present.
diff --git a/misc/drupal.js b/misc/drupal.js
-index a85b8f8..5ef493b 100644
+index a85b8f8..fd68051 100644
--- a/misc/drupal.js
+++ b/misc/drupal.js
@@ -20,6 +20,42 @@
@@ -44,7 +44,7 @@ index a85b8f8..5ef493b 100644
+ // @todo Consider backporting code from newer jQuery versions to check for
+ // a cross-domain request here, rather than using Drupal.urlIsLocal() to
+ // block scripts from all URLs that are not on the same site.
-+ if (!type && !Drupal.urlIsLocal(s.url)) {
++ if (!type && (!s || !Drupal.urlIsLocal(s.url))) {
+ var content_type = xhr.getResponseHeader('content-type') || '';
+ if (content_type.indexOf('javascript') >= 0) {
+ // Default to a safe data type.