bigbluebutton / greenlight

A really simple end-user interface for your BigBlueButton server.
GNU Lesser General Public License v3.0
789 stars 3.8k forks source link

Host header #5765

Closed SilentFlameCR closed 4 months ago

SilentFlameCR commented 5 months ago

Fixes #5625 Added option to pass URL_HOST as an optional env variable which fixes the host-header issue. Below is a screenshot of the test with cmd curl http://localhost:3000/ -H "X-Forwarded-Host: evil.com" | grep property as the image shows the og:image no longer shows as content from evil.com as I had the URL_HOST var set to http://localhost:3000

image

sonarcloud[bot] commented 4 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

sternix commented 3 months ago

Thank you,