Add extra safety

This commit is contained in:
Sam 2015-08-25 12:05:15 +10:00
parent 2c59ad3dd3
commit 4e37bcc3e2
1 changed files with 20 additions and 10 deletions

View File

@ -93,13 +93,21 @@ class StaticController < ApplicationController
# a huge expiry, we also cache these assets in nginx so it bypassed if needed
def favicon
data = DistributedMemoizer.memoize('favicon' + SiteSetting.favicon_url, 60*60*24) do
data = DistributedMemoizer.memoize('favicon' + SiteSetting.favicon_url, 60*30) do
begin
file = FileHelper.download(SiteSetting.favicon_url, 50.kilobytes, "favicon.png")
data = file.read
file.unlink
data
rescue => e
Rails.logger.warn("Invalid favicon_url #{SiteSetting.favicon_url}: #{e}\n#{e.backtrace}")
""
end
end
if data.bytesize == 0
render text: UserAvatarsController::DOT, content_type: "image/gif"
else
expires_in 1.year, public: true
response.headers["Expires"] = 1.year.from_now.httpdate
response.headers["Content-Length"] = data.bytesize.to_s
@ -107,6 +115,8 @@ class StaticController < ApplicationController
render text: data, content_type: "image/png"
end
end
def cdn_asset
path = File.expand_path(Rails.root + "public/assets/" + params[:path])