Project

General

Custom queries

Profile

Actions

Bug #6589

closed

Trusted host list seems to be ignored

Added by Martin Milata almost 11 years ago. Updated almost 7 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

The trusted host list does not seem to be used (migrate_settings.rb only moves the configuration value around).

~/smart-proxy$ git grep -l trusted_hosts       
config/settings.yml.example
extra/migrate_settings.rb
test/migration_settings.yml
test/migration_test.rb

If you decide to bring back the check, I would really appreciate if it was possible to exclude some REST API paths from the check because the ABRT plugin needs to accept problem reports even from untrusted hosts.


Related issues 1 (0 open1 closed)

Has duplicate Smart Proxy - Bug #5651: The 'trusted_hosts' config key has an unintuitive (and potentially dangerous) behaviorDuplicate05/09/2014Actions
Actions #4

Updated by Dominic Cleal over 10 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF