Skip to content

v3.26.2

Choose a tag to compare

@github-actions github-actions released this 18 Sep 17:48
· 20 commits to main since this release
  • dsh: /modlens/paste answers same-origin loopback only (#107). The paste route wrote to disk and disclosed the takeover verdict without the fence /modlens/config already had, so a page rebound onto loopback, or a cross-site page on the same machine, could plant a file in the paste store and, by repeating it, push the store over its ceiling and sweep away pastes a live session still had to read. Both branches now run the same isTrustedRequest check as the config route: a non-loopback Host, Sec-Fetch-Site: cross-site, or an Origin that does not match the Host is refused with 403 and nothing is written. The client treats that 403 like a 404 and stands down for the page, so a refused paste goes native at once instead of being taken and lost for the rest of the verdict window; the settings card does the same and does not mount. The refusal line is one shared constant, and both routes' tests assert it. A dsh opened over a LAN address loses paste-to-path and the settings card, which is the config route's existing behavior. Thanks to @nanami-0713 for the report.