git-annex/doc/devblog/day_501__security_hole_part_3.mdwn
Joey Hess 8703fdd3b7
add
2018-06-17 16:13:45 -04:00

13 lines
487 B
Markdown

Got the IP address restrictions for http implemented. (Except for http
proxies.)
Unforunately as part of this, had to make youtube-dl and curl not be used
by default. The annex.security.allowed-http-addresses config has to be
opened up by the user in order to use those external commands, since they
can follow arbitrary redirects.
Also thought some more about how external special remotes might be
affected, and sent their authors' a heads-up.
[[!meta date="June 17 2018 4:00 pm"]]