You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
require_god har et stort sikkerhetsproblem nå ettersom de ikke sjekker at ressursen og brukeren hører til samme realm. Det gir i praksis alle guder mulighet til å laste alle ressurser i systemet.
The text was updated successfully, but these errors were encountered:
I started looking into this, and we can't just assume that the request.host is going to map to the realm, because people can make requests to a different host.
We actually need to verify against the resource(s) that are being fetched, and we won't know this until we've actually fetched the resource.
I don't see how we can implement the realm check in require_god and require_identity
require_god har et stort sikkerhetsproblem nå ettersom de ikke sjekker at ressursen og brukeren hører til samme realm. Det gir i praksis alle guder mulighet til å laste alle ressurser i systemet.
The text was updated successfully, but these errors were encountered: