Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Q: Should there be an option to whitelist certain urls/hostnames? #6

Closed
jrochkind opened this issue Nov 19, 2018 · 2 comments
Closed

Comments

@jrochkind
Copy link
Contributor

To avoid user-submitted data being able to download from any arbitrary url?

@janko
Copy link
Member

janko commented Nov 20, 2018

Yeah, that would be useful.

For example, when using shrine-tus you'll almost certainly want to allow only URLs from the tus server that you're using. So if support for host whitelisting gets added here, shrine-tus will benefit from that as well.

@janko
Copy link
Member

janko commented Nov 23, 2018

I thought about this again, I think whitelisting functionality belongs outside of shrine-url. Since it's possible to validate the URL before assigning it as the attachment, there is no need to provide additional validation mechanism inside shrine-url.

@janko janko closed this as completed Nov 23, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants