SECURITY: Remove bypass for base_url (#19995)

The check used to be necessary because we validated the referrer too and
this bypass was a workaround a bug that is present in some browsers that
do not send the correct referrer.
This commit is contained in:
Bianca Nenciu
2023-01-25 13:50:45 +02:00
committed by GitHub
parent d5745d34c2
commit cd7c8861ae
2 changed files with 2 additions and 5 deletions

View File

@ -45,9 +45,6 @@ class EmbeddableHost < ActiveRecord::Base
def self.url_allowed?(url)
return false if url.nil?
# Work around IFRAME reload on WebKit where the referer will be set to the Forum URL
return true if url&.starts_with?(Discourse.base_url) && EmbeddableHost.exists?
uri =
begin
URI(UrlHelper.normalized_encode(url))