Skip to content

Restrict allowed curl parameters#7979

Merged
Alkarex merged 1 commit intoFreshRSS:edgefrom
Inverle:restrict-curl-params
Sep 18, 2025
Merged

Restrict allowed curl parameters#7979
Alkarex merged 1 commit intoFreshRSS:edgefrom
Inverle:restrict-curl-params

Conversation

@Inverle
Copy link
Member

@Inverle Inverle commented Sep 18, 2025

For additional safety, also making sure in this PR that CURLOPT_COOKIEFILE is only allowed as an empty string during import.

@Alkarex Alkarex added this to the 1.27.1 milestone Sep 18, 2025
@Alkarex Alkarex merged commit 0553421 into FreshRSS:edge Sep 18, 2025
1 check passed
@Inverle Inverle deleted the restrict-curl-params branch September 22, 2025 15:19
Alkarex pushed a commit that referenced this pull request Sep 25, 2025
Rework #7979 
Forgot to change `httpGet()`, which is used in multiple places
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants