From 995f9c7348fcc6dd25a95f81030e7d3b6f04d6c3 Mon Sep 17 00:00:00 2001
From: Michiel de Jong <michiel@unhosted.org>
Date: Sat, 9 Jun 2012 21:03:50 +0200
Subject: [PATCH] sanitize scope and host

---
 apps/remoteStorage/auth.php | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/apps/remoteStorage/auth.php b/apps/remoteStorage/auth.php
index 8cbd4aa20f..99e2272d3a 100644
--- a/apps/remoteStorage/auth.php
+++ b/apps/remoteStorage/auth.php
@@ -44,9 +44,9 @@ foreach($_GET as $k => $v) {
     $userId=$v;
   } else if($k=='redirect_uri'){
     $appUrlParts=explode('/', $v);
-    $appUrl = $appUrlParts[2];//bit dodgy i guess
+    $appUrl = htmlentities($appUrlParts[2]);//TODO: check if this is equal to client_id
   } else if($k=='scope'){
-    $categories=$v;
+    $categories=htmlentities($v);
   }
 }
 $currUser = OCP\USER::getUser();
-- 
GitLab