fixed Host header vulnerability #1196
This commit is contained in:
@@ -58,7 +58,8 @@ response.form_label_separator = myconf.get('forms.separator') or ''
|
||||
|
||||
from gluon.tools import Auth, Service, PluginManager
|
||||
|
||||
auth = Auth(db, host=myconf.get('host.name'))
|
||||
# host names must be a list of allowed host names (glob syntax allowed)
|
||||
auth = Auth(db, host_names=myconf.get('host.names'))
|
||||
service = Service()
|
||||
plugins = PluginManager()
|
||||
|
||||
|
||||
@@ -8,7 +8,7 @@ generator = Web2py Web Framework
|
||||
|
||||
; Host configuration
|
||||
[host]
|
||||
name = localhost
|
||||
names = localhost:*, 127.0.0.1:*, *:*, *
|
||||
|
||||
; db configuration
|
||||
[db]
|
||||
|
||||
Reference in New Issue
Block a user