Fix #2112 : World readable tmp directory in json_api

This commit is contained in:
baconseed 2012-09-29 17:01:28 +01:00 committed by Calum Lind
parent 43390b850a
commit bb7b529c29

View file

@ -664,7 +664,8 @@ class WebApi(JSONComponent):
log.error("Reason: %s", result.getErrorMessage())
return result
tmp_file = os.path.join(tempfile.gettempdir(), url.split("/")[-1])
tempdir = tempfile.mkdtemp(prefix="delugeweb-")
tmp_file = os.path.join(tempdir, url.split("/")[-1])
log.debug("filename: %s", tmp_file)
headers = {}
if cookie: