ttrss/classes/pref
Andrew Dolgov c3d14e1fa5 - fix multiple vulnerabilities in af_proxy_http
- fix vulnerability in rewrite_relative_url() which prevented some URLs from being properly absolutized
- fetch_file_contents: validate all URLs before requesting them
- validate URLs: explicitly whitelist http and https scheme, forbid everything else
- DiskCache/cached_url: only serve whitelisted content types (images, video)
- simplify filename/URL handling code, remove and consolidate some less-used functions
2020-09-14 19:46:52 +03:00
..
feeds.php - fix multiple vulnerabilities in af_proxy_http 2020-09-14 19:46:52 +03:00
filters.php prefs: show disabled filters properly on mysql 2020-07-01 09:49:53 +03:00
labels.php Fix button focus issues 2019-04-14 12:01:52 +02:00
prefs.php allow overriding built-in templates via templates.local 2020-03-13 14:40:35 +03:00
system.php event log: simplify styles, prevent horizontal scrolling 2019-05-31 10:31:43 +03:00
users.php move more globals to more appropriate places 2019-06-20 08:40:02 +03:00