HomePhorge

Lock `uri.allowed-protocols` in Config

Description

Lock uri.allowed-protocols in Config

Summary: This allows administrative overreach. Administrators can enable javascript: and then XSS things if this isn't locked.

Test Plan: Viewed value on web UI, verified it was locked.

Reviewers: btrahan

Reviewed By: btrahan

CC: aran

Differential Revision: https://secure.phabricator.com/D6975

Details

Provenance
epriestleyAuthored on Sep 13 2013, 11:48 AM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rPde10d919633b: Make normalization of "#yolo" hashtags less aggressive
Branches
Unknown
Tags
Unknown

Event Timeline