aboutsummaryrefslogtreecommitdiffstats
path: root/phpBB/phpbb/db
diff options
context:
space:
mode:
authorMarc Alexander <admin@m-a-styles.de>2019-04-17 08:54:51 +0200
committerMarc Alexander <admin@m-a-styles.de>2019-04-17 08:54:51 +0200
commitdc5a167c429a3813d66b0ae3d14242650466cac6 (patch)
tree9a23a88f7bc2d482cef19f42f437bf77be31f41f /phpBB/phpbb/db
parent507efee633fee769e7e2af4a2b298c951193f800 (diff)
downloadforums-dc5a167c429a3813d66b0ae3d14242650466cac6.tar
forums-dc5a167c429a3813d66b0ae3d14242650466cac6.tar.gz
forums-dc5a167c429a3813d66b0ae3d14242650466cac6.tar.bz2
forums-dc5a167c429a3813d66b0ae3d14242650466cac6.tar.xz
forums-dc5a167c429a3813d66b0ae3d14242650466cac6.zip
[ticket/security/231] Disable remote avatar functionality & add warning
SECURITY-231
Diffstat (limited to 'phpBB/phpbb/db')
-rw-r--r--phpBB/phpbb/db/migration/data/v32x/disable_remote_avatar.php34
1 files changed, 34 insertions, 0 deletions
diff --git a/phpBB/phpbb/db/migration/data/v32x/disable_remote_avatar.php b/phpBB/phpbb/db/migration/data/v32x/disable_remote_avatar.php
new file mode 100644
index 0000000000..b08833fad4
--- /dev/null
+++ b/phpBB/phpbb/db/migration/data/v32x/disable_remote_avatar.php
@@ -0,0 +1,34 @@
+<?php
+/**
+ *
+ * This file is part of the phpBB Forum Software package.
+ *
+ * @copyright (c) phpBB Limited <https://www.phpbb.com>
+ * @license GNU General Public License, version 2 (GPL-2.0)
+ *
+ * For full copyright and license information, please see
+ * the docs/CREDITS.txt file.
+ *
+ */
+
+namespace phpbb\db\migration\data\v32x;
+
+use phpbb\db\migration\migration;
+
+class disable_remote_avatar extends migration
+{
+ static public function depends_on()
+ {
+ return array(
+ '\phpbb\db\migration\data\v32x\v325',
+ );
+ }
+
+ public function update_data()
+ {
+ return array(
+ array('config.update', array('allow_avatar_remote', '0')),
+ array('config.update', array('allow_avatar_remote_upload', '0')),
+ );
+ }
+}