5
0
Fork 0
mirror of https://0xacab.org/sutty/sutty synced 2024-07-01 11:56:08 +00:00

fix: solo validar el host de archivo subido si estamos validando hosts #13181
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful

This commit is contained in:
f 2023-04-20 18:30:10 -03:00
parent 47ffb7ebca
commit 7c6f3ca8b4

View file

@ -56,8 +56,13 @@ class MetadataContent < MetadataTemplate
uri = URI element['src']
# No permitimos recursos externos
raise URI::Error unless Rails.application.config.hosts.include?(uri.hostname)
# No permitimos recursos externos, solo si sabemos cuales son
# los recursos locales
if Rails.application.config.hosts.present?
unless Rails.application.config.hosts.include?(uri.hostname)
raise URI::Error
end
end
element['src'] = convert_src_to_internal_path uri