Project

General

Profile

Actions

Bug #6589

closed

Trusted host list seems to be ignored

Added by Martin Milata over 10 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

The trusted host list does not seem to be used (migrate_settings.rb only moves the configuration value around).

~/smart-proxy$ git grep -l trusted_hosts       
config/settings.yml.example
extra/migrate_settings.rb
test/migration_settings.yml
test/migration_test.rb

If you decide to bring back the check, I would really appreciate if it was possible to exclude some REST API paths from the check because the ABRT plugin needs to accept problem reports even from untrusted hosts.


Related issues 1 (0 open1 closed)

Has duplicate Smart Proxy - Bug #5651: The 'trusted_hosts' config key has an unintuitive (and potentially dangerous) behaviorDuplicate05/09/2014Actions
Actions

Also available in: Atom PDF