]> git.p6c8.net - jirafeau/pcanterino.git/blobdiff - f.php
pat pat - ci linting
[jirafeau/pcanterino.git] / f.php
diff --git a/f.php b/f.php
index 922668f0002d26f09bc356b90eea60ac7d1e75cd..f0a3d12d5b5b2347c6af3473ccebb43560a7954f 100644 (file)
--- a/f.php
+++ b/f.php
@@ -171,7 +171,7 @@ if (!empty($link['key'])) {
         require(JIRAFEAU_ROOT.'lib/template/footer.php');
         exit;
     } else {
-        if (hash_equals($link['key'], md5($_POST['key']))) {
+        if (hash_equals($link['key'], hash('sha256', $_POST['key']))) {
             $password_challenged = true;
         } else {
             sleep(2);
@@ -231,6 +231,7 @@ if (!jirafeau_is_viewable($link['mime_type']) || !$cfg['preview'] || $do_downloa
     header('Content-Disposition: attachment; filename="' . $link['file_name'] . '"');
 } else {
     header('Content-Disposition: filename="' . $link['file_name'] . '"');
+    header('X-Content-Type-Options: nosniff');
 }
 header('Content-Type: ' . $link['mime_type']);
 if ($cfg['file_hash'] == "md5") {

patrick-canterino.de