diff options
author | Ferdinand Thiessen <rpm@fthiessen.de> | 2023-01-26 21:08:10 +0100 |
---|---|---|
committer | Ferdinand Thiessen <rpm@fthiessen.de> | 2023-02-16 22:55:18 +0100 |
commit | f655f83c840f30781999cd84d800cb2cc27983bf (patch) | |
tree | 8df8276fc81af6224b936482109ca49be9cb5013 /.devcontainer | |
parent | 57c974f421e8a409ef728fae0b1ac670a70c7f11 (diff) | |
download | nextcloud-server-f655f83c840f30781999cd84d800cb2cc27983bf.tar.gz nextcloud-server-f655f83c840f30781999cd84d800cb2cc27983bf.zip |
fix(CORS): CORS should only be bypassed on `PublicPage` if not logged in to prevent CSRF attack vectors
Signed-off-by: Ferdinand Thiessen <rpm@fthiessen.de>
Diffstat (limited to '.devcontainer')
0 files changed, 0 insertions, 0 deletions