Commit 603fccf1 authored by kaniini's avatar kaniini
Browse files

activitypub: fetch_object_from_id(): prefer `actor` over `attributedTo` to avoid spoofing

parent 9c8adfb6
Pipeline #4532 passed with stages
in 7 minutes and 20 seconds
......@@ -747,7 +747,7 @@ def fetch_object_from_id(id) do
"type" => "Create",
"to" => data["to"],
"cc" => data["cc"],
"actor" => data["attributedTo"],
"actor" => data["actor"] || data["attributedTo"],
"object" => data
},
:ok <- Transmogrifier.contain_origin(id, params),
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment