also block autocomplete for % / _

This commit is contained in:
Shish 2019-04-26 10:31:23 +01:00
parent bc45944ac9
commit bef1628b08

View File

@ -14,7 +14,12 @@ class AutoComplete extends Extension {
if($event->page_matches("api/internal/autocomplete")) {
if(!isset($_GET["s"])) return;
$s = strtolower($_GET["s"]);
if(strlen($s) == 0 || strlen($s) > 32) return;
if(
$s == '' ||
$s == '_' ||
$s == '%' ||
strlen($s) > 32
) return;
//$limit = 0;
$cache_key = "autocomplete-$s";