From aacf637cc08aec6b885b21e05f19f04721532940 Mon Sep 17 00:00:00 2001 From: Alan Knowles Date: Mon, 23 Dec 2019 11:19:41 +0800 Subject: [PATCH] permit access to mailing list message images --- Images.php | 4 +++- MessagePreview.php | 1 + 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/Images.php b/Images.php index 1d075c9a..bfda2826 100644 --- a/Images.php +++ b/Images.php @@ -42,7 +42,9 @@ class Pman_Core_Images extends Pman { // tables that do not need authentication checks before serving. - var $public_image_tables = array(); + var $public_image_tables = array( + 'crm_mailing_list_message' // we know these are ok... + ); var $sizes = array( '100', diff --git a/MessagePreview.php b/MessagePreview.php index f59cde17..e12a0312 100644 --- a/MessagePreview.php +++ b/MessagePreview.php @@ -20,6 +20,7 @@ class Pman_Core_MessagePreview extends Pman function get($v, $opts=array()) { + if(empty($_REQUEST['_id']) || empty($_REQUEST['_table'])){ $this->jerr('Missing Options'); } -- 2.39.2