From 99b25c30da85c0e055fc43aae7ab8c2dd19d1fb0 Mon Sep 17 00:00:00 2001 From: Daniel Kulp Date: Tue, 24 Dec 2024 16:48:24 +0000 Subject: [PATCH] Return a 404 if api/file/sequence called directly with no file --- www/api/controllers/files.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/www/api/controllers/files.php b/www/api/controllers/files.php index 6b8e64050..09d270b1f 100644 --- a/www/api/controllers/files.php +++ b/www/api/controllers/files.php @@ -385,7 +385,8 @@ function GetFileImpl($dir, $filename, $lines, $play, $attach) $filename = substr($filename, 8); } - if (!file_exists($dir . '/' . $filename)) { + if (!file_exists($dir . '/' . $filename) || !is_file($dir . '/' . $filename)) { + http_response_code(404); echo "File $dir/$filename does not exist."; return; }