Browse Source

Merge pull request #39996 from nextcloud/bugfix/noid/fix-header-regression

fix(middleware): Fix header injection for bruteforce middleware
pull/40046/head
Joas Schilling 3 years ago
committed by GitHub
parent
commit
613cd16583
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
  1. 6
      lib/private/AppFramework/Middleware/Security/BruteForceMiddleware.php

6
lib/private/AppFramework/Middleware/Security/BruteForceMiddleware.php

@ -130,11 +130,7 @@ class BruteForceMiddleware extends Middleware {
}
if ($this->delaySlept) {
$headers = $response->getHeaders();
if (!isset($headers['X-Nextcloud-Bruteforce-Throttled'])) {
$headers['X-Nextcloud-Bruteforce-Throttled'] = $this->delaySlept . 'ms';
$response->setHeaders($headers);
}
$response->addHeader('X-Nextcloud-Bruteforce-Throttled', $this->delaySlept . 'ms');
}
return parent::afterController($controller, $methodName, $response);

Loading…
Cancel
Save