mirror of https://github.com/mastodon/mastodon
Right now, this includes three endpoints: host-meta, webfinger, and change-password. host-meta and webfinger are publicly available and do not use any authentication. Nothing bad can be done by accessing them in a user's browser. change-password being CORS-enabled will only reveal the URL it redirects to (which is /auth/edit) but not anything about the actual /auth/edit page, because it does not have CORS enabled. The documentation for hosting an instance on a different domain should also be updated to point out that Access-Control-Allow-Origin: * should be set at a minimum for the /.well-known/host-meta redirect to allow browser-based non-proxied instance discovery. |
7 years ago | |
---|---|---|
.. | ||
0_post_deployment_migrations.rb | 7 years ago | |
1_hosts.rb | 7 years ago | |
active_model_serializers.rb | 7 years ago | |
application_controller_renderer.rb | 9 years ago | |
assets.rb | 7 years ago | |
backtrace_silencers.rb | 9 years ago | |
blacklists.rb | 8 years ago | |
chewy.rb | 7 years ago | |
content_security_policy.rb | 7 years ago | |
cookies_serializer.rb | 9 years ago | |
cors.rb | 7 years ago | |
devise.rb | 7 years ago | |
doorkeeper.rb | 7 years ago | |
fast_blank.rb | 8 years ago | |
ffmpeg.rb | 7 years ago | |
filter_parameter_logging.rb | 8 years ago | |
http_client_proxy.rb | 7 years ago | |
httplog.rb | 8 years ago | |
inflections.rb | 8 years ago | |
instrumentation.rb | 8 years ago | |
kaminari_config.rb | 8 years ago | |
mime_types.rb | 8 years ago | |
oj.rb | 7 years ago | |
omniauth.rb | 7 years ago | |
open_uri_redirection.rb | 7 years ago | |
pagination.rb | 8 years ago | |
paperclip.rb | 7 years ago | |
premailer_rails.rb | 7 years ago | |
rack_attack.rb | 7 years ago | |
rack_attack_logging.rb | 7 years ago | |
redis.rb | 8 years ago | |
session_activations.rb | 8 years ago | |
session_store.rb | 7 years ago | |
sidekiq.rb | 7 years ago | |
simple_form.rb | 7 years ago | |
single_user_mode.rb | 8 years ago | |
statsd.rb | 7 years ago | |
stoplight.rb | 7 years ago | |
strong_migrations.rb | 8 years ago | |
suppress_csrf_warnings.rb | 7 years ago | |
trusted_proxies.rb | 8 years ago | |
twitter_regex.rb | 7 years ago | |
vapid.rb | 7 years ago | |
wrap_parameters.rb | 9 years ago |