mirror of
https://github.com/zedeus/nitter
synced 2026-09-06 07:09:31 +00:00
Fix SSRF in /video proxy and API JSON injection
Validate the target host on the /video media route with isTwitterUrl() (mirroring /pic) and reject non-http(s) schemes, and stop the media proxy following redirects off the validated host. JSON-escape user-controlled GraphQL cursors and build id variables with packedjson so untrusted input can't break out of the query. Warn on startup when the insecure default hmacKey is in use. Fixes #1411
This commit is contained in:
parent
7b27c2c629
commit
44b2f096f6
7 changed files with 69 additions and 22 deletions
|
|
@ -161,8 +161,6 @@ const
|
|||
|
||||
articleFieldToggles* = """{"withArticleRichContentState":true,"withArticlePlainText":false,"withArticleSummaryText":true,"withArticleVoiceOver":true}"""
|
||||
|
||||
communityVars* = """{"communityId":"$1"}"""
|
||||
|
||||
communityTweetsVars* = """{
|
||||
"communityId": "$1", $2
|
||||
"count": 20,
|
||||
|
|
|
|||
Loading…
Reference in a new issue