security: spoofing hardening
Avoid fake direction attacks when fetching any AP object. Transmogrifier.contain_origin()
is still useful for checking the actor case.
Closes: #380, #381, #382.
Edited by kaniini
Avoid fake direction attacks when fetching any AP object. Transmogrifier.contain_origin()
is still useful for checking the actor case.
Closes: #380, #381, #382.