Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Admin API DNS Rebinding mitigation #62

Merged
merged 1 commit into from
Jun 14, 2023
Merged

Conversation

DerTiedemann
Copy link
Contributor

@DerTiedemann DerTiedemann commented Apr 21, 2023

Depends on chain4travel/caminogo#263
This PR adds a check so that the admin API has to be enabled with the awareness that its running on localhost. A new flag has to be set in order for it to be started, otherwise the node crashes with an error.

This is in order to sidestep the DNS Rebinding issue.

@DerTiedemann DerTiedemann changed the base branch from chain4travel to dev June 7, 2023 08:45
knikos
knikos previously approved these changes Jun 9, 2023
@DerTiedemann DerTiedemann dismissed knikos’s stale review June 14, 2023 10:09

The merge-base changed after approval.

@DerTiedemann DerTiedemann force-pushed the jax/dns_rebinding_fix branch 4 times, most recently from 476a119 to 1f560d8 Compare June 14, 2023 12:47
c4t-ag
c4t-ag previously approved these changes Jun 14, 2023
@DerTiedemann DerTiedemann merged commit 4de2490 into dev Jun 14, 2023
6 of 7 checks passed
@knikos knikos deleted the jax/dns_rebinding_fix branch June 26, 2023 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
3 participants