Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Only allow exact id matches #4849

Merged
merged 1 commit into from
Mar 30, 2024
Merged

Only allow exact id matches #4849

merged 1 commit into from
Mar 30, 2024

Conversation

mei23
Copy link
Owner

@mei23 mei23 commented Mar 30, 2024

Summary

Strict AP object id check
The id property of the retrieved object must match the final redirect URL actually attempted.

https://akkoma.dev/AkkomaGang/akkoma/commit/8684964c5d03f6c70f73730b3f1ad26784ffb004
https://firefish.dev/firefish/firefish/-/merge_requests/10718/commits

多分、ドライブファイル等にAP Objectっぽいのを上げられた時にfakeオブジェクトが出来てしまう場合とかの受け側の対策。
現状のContent-Typeチェックである程度大丈夫な気はするけど、このチェックによってドライブファイル等アップロード後のURLが予測困難な場合攻撃が困難になるから多層防御として有効?

Co-authored-by: Laura Hausmann <laura@hausmann.dev>
@mei23 mei23 merged commit 410ec34 into mei-m544 Mar 30, 2024
3 checks passed
@mei23 mei23 deleted the mei-f-240311 branch March 30, 2024 16:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant