w3c / activitypub

http://w3c.github.io/activitypub/
Other
1.21k stars 77 forks source link

Checking URIs to make sure they don't refer to internal network resources #433

Open evanp opened 6 months ago

evanp commented 6 months ago

As mentioned in [https://www.w3.org/TR/activitypub/#security-localhost localhost], one type of security attack is to use URIs for identifiers that refer to internal resources.

We should document that this is also the case for other network resources that are internal.