« Previous | Next » 

Revision 90132ee4


Added by Bastian Waidelich over 7 years ago

[BUGFIX] Prevent invocation of protected controller methods

Currently any method with an "Action" suffix is callable via the
default request handling if a corresponding route exists.

For the fallback routes provided by Flow this is the case for the
``initialize*Action()`` methods that are called before the actual
action invocation.

This change adds a check for the visibility of an action method
and only allows invocation of public methods.

Change-Id: I076a56118b5fad112adf0dba0dee7b4711cfe903
Fixes: #57410
Releases: master, 2.2, 2.1

  • added
  • modified
  • copied
  • renamed
  • deleted