1
0
mirror of https://github.com/mastodon/mastodon.git synced 2024-12-18 09:05:06 +01:00
mastodon/app/models/account
David Leadbeater 69378eac99
Don't allow URLs that contain non-normalized paths to be verified ()
* Don't allow URLs that contain non-normalized paths to be verified

This stops things like https://example.com/otheruser/../realuser where
"/otheruser" appears to be the verified URL, but the actual URL being
verified is "/realuser" due to the "/../".

Also fix a test to use 'https', so it is testing the right thing, now
that since  https is required.

* missing do
2022-11-20 19:28:13 +01:00
..
field.rb Don't allow URLs that contain non-normalized paths to be verified () 2022-11-20 19:28:13 +01:00