Roundup Tracker - Issues

Message8027

Author rouilj
Recipients rouilj
Date 2024-05-02.01:53:16
Message-id <1714614796.99.0.187358881176.issue2551345@roundup.psfhosted.org>
In-reply-to
It appears that you can request a static file from a Roundup instance from any
web page. The origin (CSRF) and other checks are not applied.

Anti leeching can be implemented by a proxy server.

So not a major issue, but it would be nice to provide a native method to
prevent inline linking/leeching.
History
Date User Action Args
2024-05-02 01:53:17rouiljsetrecipients: + rouilj
2024-05-02 01:53:17rouiljsetmessageid: <1714614796.99.0.187358881176.issue2551345@roundup.psfhosted.org>
2024-05-02 01:53:16rouiljlinkissue2551345 messages
2024-05-02 01:53:16rouiljcreate