Fix a security issue that author_signature is not checked on the to-downstream...
Fix a security issue that author_signature is not checked on the to-downstream receive of a federated relayable entity, allowing to forge relayables if you are an owner of the pod where a parent object is stored. closes #6539
parent
922d26f9
Aucune branche associée trouvée
Aucune étiquette associée trouvée
Affichage de
- Changelog.md 2 ajouts, 0 suppressionChangelog.md
- lib/diaspora/relayable.rb 6 ajouts, 0 suppressionlib/diaspora/relayable.rb
- spec/integration/federation/federation_messages_generation.rb 7 ajouts, 0 suppression.../integration/federation/federation_messages_generation.rb
- spec/integration/federation/shared_receive_relayable.rb 8 ajouts, 0 suppressionspec/integration/federation/shared_receive_relayable.rb
Veuillez vous inscrire ou vous se connecter pour commenter