mirror of
https://github.com/discourse/discourse.git
synced 2025-05-25 09:57:25 +08:00
SECURITY: Remove bypass for base_url (#19995)
The check used to be necessary because we validated the referrer too and this bypass was a workaround a bug that is present in some browsers that do not send the correct referrer.
This commit is contained in:
@ -88,8 +88,8 @@ RSpec.describe EmbeddableHost do
|
||||
expect(EmbeddableHost.url_allowed?("http://discourse.org")).to eq(true)
|
||||
end
|
||||
|
||||
it "always allow forum own URL" do
|
||||
expect(EmbeddableHost.url_allowed?(Discourse.base_url)).to eq(true)
|
||||
it "does not allow forum own URL" do
|
||||
expect(EmbeddableHost.url_allowed?(Discourse.base_url)).to eq(false)
|
||||
end
|
||||
end
|
||||
|
||||
|
Reference in New Issue
Block a user