Commit 65252af3 authored by FX Deltombe's avatar FX Deltombe
Browse files

Fix slight bug about trustedDomains regex: domains might be tampered (#467)

parent ec22ab25
......@@ -458,7 +458,7 @@ sub new {
$self->{trustedDomains} = "*"
if ( $self->{trustedDomains} =~ /(^|\s)\*(\s|$)/ );
if ( $self->{trustedDomains} and $self->{trustedDomains} ne "*" ) {
$self->{trustedDomains} =~ s#(^|\s+)\.#[^/]+.#g;
$self->{trustedDomains} =~ s#((^|\s+))\.#${1}[^/]+.#g;
$self->{trustedDomains} =
'(' . join( '|', split( /\s+/, $self->{trustedDomains} ) ) . ')';
$self->{trustedDomains} =~ s/\./\\./g;
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment