HomePhorge

Improve protection against SSRF attacks

Description

Improve protection against SSRF attacks

Summary:
Ref T6755. This improves our resistance to SSRF attacks:

  • Follow redirects manually and verify each component of the redirect chain.
  • Handle authentication provider profile picture fetches more strictly.

Test Plan:

  • Tried to download macros from various URIs which issued redirects, etc.
  • Downloaded an actual macro.
  • Went through external account workflow.

Reviewers: btrahan

Reviewed By: btrahan

Subscribers: epriestley

Maniphest Tasks: T6755

Differential Revision: https://secure.phabricator.com/D12151

Details

Provenance
epriestleyAuthored on Mar 24 2015, 6:49 PM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rP22b2b8eb893a: Fix a bad call in file chunk destruction
Branches
Unknown
Tags
Unknown

Event Timeline