Commit f0c54243 authored by Zach Copley's avatar Zach Copley

Merge branch 'testing' of gitorious.org:statusnet/mainline into testing

* 'testing' of gitorious.org:statusnet/mainline:
  Validate OStatus avatar URL before fetching.
parents 348412f9 9e3e1d3d
......@@ -839,8 +839,8 @@ class Ostatus_profile extends Memcached_DataObject
* Download and update given avatar image
* @param string $url
* @throws Exception in various failure cases
......@@ -850,6 +850,9 @@ class Ostatus_profile extends Memcached_DataObject
// We've already got this one.
if (!common_valid_http_url($url)) {
throw new ServerException(_m("Invalid avatar URL %s"), $url);
if ($this->isGroup()) {
$self = $this->localGroup();
