summaryrefslogtreecommitdiffhomepage
path: root/src/http/ngx_http_request.c
diff options
context:
space:
mode:
authorMaxim Dounin <mdounin@mdounin.ru>2012-03-05 12:49:32 +0000
committerMaxim Dounin <mdounin@mdounin.ru>2012-03-05 12:49:32 +0000
commitbe909c35b0b2ad737b701fde9c63105251800b14 (patch)
treec4c22d553d969f5880a5ec3d812a07e38db6d7dd /src/http/ngx_http_request.c
parent31b3edd003a6fd4aba0c7fd1428c062a3c57bec6 (diff)
downloadnginx-be909c35b0b2ad737b701fde9c63105251800b14.tar.gz
nginx-be909c35b0b2ad737b701fde9c63105251800b14.tar.bz2
Merge of r4473:
Core: protection from cycles with named locations and post_action. Now redirects to named locations are counted against normal uri changes limit, and post_action respects this limit as well. As a result at least the following (bad) configurations no longer trigger infinite cycles: 1. Post action which recursively triggers post action: location / { post_action /index.html; } 2. Post action pointing to nonexistent named location: location / { post_action @nonexistent; } 3. Recursive error page for 500 (Internal Server Error) pointing to a nonexistent named location: location / { recursive_error_pages on; error_page 500 @nonexistent; return 500; }
Diffstat (limited to 'src/http/ngx_http_request.c')
-rw-r--r--src/http/ngx_http_request.c4
1 files changed, 4 insertions, 0 deletions
diff --git a/src/http/ngx_http_request.c b/src/http/ngx_http_request.c
index 13cabbad5..04c4165de 100644
--- a/src/http/ngx_http_request.c
+++ b/src/http/ngx_http_request.c
@@ -2898,6 +2898,10 @@ ngx_http_post_action(ngx_http_request_t *r)
return NGX_DECLINED;
}
+ if (r->post_action && r->uri_changes == 0) {
+ return NGX_DECLINED;
+ }
+
ngx_log_debug1(NGX_LOG_DEBUG_HTTP, r->connection->log, 0,
"post action: \"%V\"", &clcf->post_action);