Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix insufficient origin validation #502

Merged
merged 1 commit into from
Feb 1, 2024

Conversation

ClearlyClaire
Copy link
Contributor

@ClearlyClaire ClearlyClaire commented Feb 1, 2024

This is a port of the fixes released today for Mastodon (see https://mastodon.social/@MastodonEngineering/111839553542311522)

Due to the severity of the issue, we recommend you merge this patch ASAP.

Please be aware that I only performed cursory verification of the patch's correct behavior, so I encourage you to take your time to review it carefully once it is deployed.

Finally, please understand that we do not officially support older versions (see https://github.com/mastodon/mastodon/blob/main/SECURITY.md for officially supported versions) nor forks, and while I exceptionally ported this patch, I am not able to ensure this will happen for any other patch going forward.

@ClearlyClaire ClearlyClaire changed the title Placeholder for 2024-02-01 security fix Fix insufficient origin validation Feb 1, 2024
@ClearlyClaire ClearlyClaire marked this pull request as ready for review February 1, 2024 15:00
@weex weex merged commit cfdc396 into magicstone-dev:main Feb 1, 2024
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants