You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
dsh: /modlens/paste answers same-origin loopback only (#107). The paste route wrote to disk and disclosed the takeover verdict without the fence /modlens/config already had, so a page rebound onto loopback, or a cross-site page on the same machine, could plant a file in the paste store and, by repeating it, push the store over its ceiling and sweep away pastes a live session still had to read. Both branches now run the same isTrustedRequest check as the config route: a non-loopback Host, Sec-Fetch-Site: cross-site, or an Origin that does not match the Host is refused with 403 and nothing is written. The client treats that 403 like a 404 and stands down for the page, so a refused paste goes native at once instead of being taken and lost for the rest of the verdict window; the settings card does the same and does not mount. The refusal line is one shared constant, and both routes' tests assert it. A dsh opened over a LAN address loses paste-to-path and the settings card, which is the config route's existing behavior. Thanks to @nanami-0713 for the report.