diff options
Diffstat (limited to 'app/Controllers/javascriptController.php')
| -rw-r--r-- | app/Controllers/javascriptController.php | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/app/Controllers/javascriptController.php b/app/Controllers/javascriptController.php index 0cbcd0bd0..f7002cba8 100644 --- a/app/Controllers/javascriptController.php +++ b/app/Controllers/javascriptController.php @@ -5,6 +5,7 @@ class FreshRSS_javascript_Controller extends FreshRSS_ActionController { /** * @var FreshRSS_ViewJavascript + * @phpstan-ignore property.phpDocType */ protected $view; @@ -53,6 +54,10 @@ class FreshRSS_javascript_Controller extends FreshRSS_ActionController { header('Pragma: no-cache'); $user = $_GET['user'] ?? ''; + if (!is_string($user) || $user === '') { + Minz_Error::error(400); + return; + } FreshRSS_Context::initUser($user); if (FreshRSS_Context::hasUserConf()) { try { |
