Skip to content

Add validating to protect against Server-side request forgery #51

@antoni-devlin

Description

@antoni-devlin

Interesting yeah I just looked through that too.
I agree with you @antoni-devlin but let's also think about how you'd mitigate this?

You don't have to come up with a solution, but might be good to make a TODO.md or a card that outlines what you think you could do about this problem?

I wonder for instance if we could do anything to validate that input 🤔

Originally posted by @huwd in #47 (comment)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions