Closed GoogleCodeExporter closed 9 years ago
Thanks for that. Have implemented the regex
I understand the concern but I am not entirely keen about removing the default
allowed sites as that makes things harder for non technical users (the whole
reason timthumb exists).
As such I have removed the possibly insecure domains (domains where you can
upload any type of content) and kept the ones that are restricted to images.
Hopefully that's a decent compromise?
Original comment by BinaryMoon
on 2 Aug 2011 at 9:59
Original issue reported on code.google.com by
mmaun...@gmail.com
on 2 Aug 2011 at 9:19Attachments: