Skip to content

Move user-specific ext.php into normal FreshRSS controller #4930

@Alkarex

Description

@Alkarex

ext.php should be limited to files not requiring login.
We need to move user-specific functionality to a normal controller to check that we are serving a file from the proper user.

Security regression from #3433
Partial fix #4928

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions