Skip to content

Commit

Permalink
don't allow dates after 3000'
Browse files Browse the repository at this point in the history
  • Loading branch information
eddierubeiz committed Oct 23, 2023
1 parent bcdc064 commit 1ab8624
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion app/controllers/catalog_controller.rb
Original file line number Diff line number Diff line change
Expand Up @@ -528,7 +528,8 @@ def catch_bad_blacklight_params
next if _facet_key == "-year_facet_isim" && range_limits == ["[* TO *]"]

unless range_limits.respond_to?(:to_hash) && range_limits[:begin].is_a?(String) && range_limits[:end].is_a?(String) &&
range_limits[:begin] =~ /\A\d*\z/ && range_limits[:end] =~ /\A\d*\z/
range_limits[:begin] =~ /\A\d*\z/ && range_limits[:end] =~ /\A\d*\z/ &&
range_limits[:begin].to_i < 3000 && range_limits[:end].to_i < 3000
render(plain: "Invalid URL query parameter range=#{param_display.call(params[:range])}", status: 400) && return
end
end
Expand Down

0 comments on commit 1ab8624

Please sign in to comment.