Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rpcserver: Add more strict request origin check. #2676

Merged
merged 1 commit into from
Jul 15, 2021

Commits on Jul 8, 2021

  1. rpcserver: Add more strict request origin check.

    This makes the CORS policy for websocket clients more strict by ensuring
    any requests from other domains are rejected.  It is worth noting that,
    in practice, the current less strict mechanism is secure due to both the
    use of a self-signed TLS certificate and the requirement for
    authentication to issue any commands, but further hardening is still
    desirable.
    davecgh committed Jul 8, 2021
    Configuration menu
    Copy the full SHA
    e917dcb View commit details
    Browse the repository at this point in the history