diff --git a/app/controllers/api/account.php b/app/controllers/api/account.php index ed04b003d8..ff796f2209 100644 --- a/app/controllers/api/account.php +++ b/app/controllers/api/account.php @@ -2112,15 +2112,6 @@ Http::post('/v1/account/tokens/magic-url') throw new Exception(Exception::GENERAL_SMTP_DISABLED, 'SMTP disabled'); } - $url = \parse_url($url); - $url['path'] = \htmlentities($url['path'] ?? ''); - $url = (isset($url['scheme']) ? $url['scheme'] . '://' : '') . - (isset($url['user']) ? $url['user'] . (isset($url['pass']) ? ':' . $url['pass'] : '') . '@' : '') . - (isset($url['host']) ? $url['host'] : '') . - (isset($url['port']) ? ':' . $url['port'] : '') . - (isset($url['path']) ? $url['path'] : '') . - (isset($url['query']) ? '?' . $url['query'] : '') . - (isset($url['fragment']) ? '#' . $url['fragment'] : ''); if ($phrase === true) { $phrase = Phrase::generate(); @@ -3582,16 +3573,6 @@ Http::post('/v1/account/recovery') throw new Exception(Exception::GENERAL_SMTP_DISABLED, 'SMTP Disabled'); } - $url = \parse_url($url); - $url['path'] = \htmlentities($url['path'] ?? ''); - $url = (isset($url['scheme']) ? $url['scheme'] . '://' : '') . - (isset($url['user']) ? $url['user'] . (isset($url['pass']) ? ':' . $url['pass'] : '') . '@' : '') . - (isset($url['host']) ? $url['host'] : '') . - (isset($url['port']) ? ':' . $url['port'] : '') . - (isset($url['path']) ? $url['path'] : '') . - (isset($url['query']) ? '?' . $url['query'] : '') . - (isset($url['fragment']) ? '#' . $url['fragment'] : ''); - $email = \strtolower($email); $profile = $dbForProject->findOne('users', [ @@ -3907,16 +3888,6 @@ Http::post('/v1/account/verifications/email') throw new Exception(Exception::USER_EMAIL_NOT_FOUND); } - $url = \parse_url($url); - $url['path'] = \htmlentities($url['path'] ?? ''); - $url = (isset($url['scheme']) ? $url['scheme'] . '://' : '') . - (isset($url['user']) ? $url['user'] . (isset($url['pass']) ? ':' . $url['pass'] : '') . '@' : '') . - (isset($url['host']) ? $url['host'] : '') . - (isset($url['port']) ? ':' . $url['port'] : '') . - (isset($url['path']) ? $url['path'] : '') . - (isset($url['query']) ? '?' . $url['query'] : '') . - (isset($url['fragment']) ? '#' . $url['fragment'] : ''); - if ($user->getAttribute('emailVerification')) { throw new Exception(Exception::USER_EMAIL_ALREADY_VERIFIED); } diff --git a/app/controllers/api/teams.php b/app/controllers/api/teams.php index 28d58ec770..7a3370a4ab 100644 --- a/app/controllers/api/teams.php +++ b/app/controllers/api/teams.php @@ -498,18 +498,6 @@ Http::post('/v1/teams/:teamId/memberships') $isAppUser = User::isApp($authorization->getRoles()); $isPrivilegedUser = User::isPrivileged($authorization->getRoles()); - if (!empty($url)) { - $url = \parse_url($url); - $url['path'] = \htmlentities($url['path'] ?? ''); - $url = (isset($url['scheme']) ? $url['scheme'] . '://' : '') . - (isset($url['user']) ? $url['user'] . (isset($url['pass']) ? ':' . $url['pass'] : '') . '@' : '') . - (isset($url['host']) ? $url['host'] : '') . - (isset($url['port']) ? ':' . $url['port'] : '') . - (isset($url['path']) ? $url['path'] : '') . - (isset($url['query']) ? '?' . $url['query'] : '') . - (isset($url['fragment']) ? '#' . $url['fragment'] : ''); - - } if (empty($url)) { if (!$isAppUser && !$isPrivilegedUser) { throw new Exception(Exception::GENERAL_ARGUMENT_INVALID, 'URL is required');