mirror of
https://codeberg.org/forgejo/forgejo.git
synced 2026-07-22 01:17:57 +00:00
**Backport:** https://codeberg.org/forgejo/forgejo/pulls/11795 Adds an extra check to ensure the `keyId` and `actorId` included in signed requests and actor records point back to the originating host. This check prevents server-side request forgery (SSRF) attacks where a carefully crafted request could be used to trick a federation server into making requests to arbitrary hosts and ports. ### Tests for Go changes - I added test coverage for Go changes... - [x] in their respective `*_test.go` for unit tests. - [x] in the `tests/integration` directory if it involves interactions with a live Forgejo server. - I ran... - [x] `make pr-go` before pushing Co-authored-by: elle <0xllx0@noreply.codeberg.org> Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13351 Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org> |
||
|---|---|---|
| .. | ||
| client.go | ||
| client_test.go | ||
| main_test.go | ||
| user_settings.go | ||
| user_settings_test.go | ||