Usage of "escapeshellarg" has been added to "yii\console\controllers\AssetController::actionCompress()".

This commit is contained in:
Klimov Paul
2013-05-16 20:51:02 +03:00
parent d3beeb7ddc
commit 2c930ae2cd

View File

@@ -365,8 +365,8 @@ EOD
$tmpFile = $outputFile . '.tmp';
$this->combineJsFiles($inputFiles, $tmpFile);
$log = shell_exec(strtr($this->jsCompressor, array(
'{from}' => $tmpFile,
'{to}' => $outputFile,
'{from}' => escapeshellarg($tmpFile),
'{to}' => escapeshellarg($outputFile),
)));
@unlink($tmpFile);
} else {
@@ -385,8 +385,8 @@ EOD
$tmpFile = $outputFile . '.tmp';
$this->combineCssFiles($inputFiles, $tmpFile);
$log = shell_exec(strtr($this->cssCompressor, array(
'{from}' => $tmpFile,
'{to}' => $outputFile,
'{from}' => escapeshellarg($tmpFile),
'{to}' => escapeshellarg($outputFile),
)));
@unlink($tmpFile);
} else {