Skip to content

security: spoofing hardening

kaniini requested to merge security/spoofing-hardening into develop

Avoid fake direction attacks when fetching any AP object. Transmogrifier.contain_origin() is still useful for checking the actor case.

Closes: #380, #381, #382.

Edited by kaniini

Merge request reports

Loading