Skip to content

Conversation

@na9da
Copy link
Contributor

@na9da na9da commented Dec 4, 2025

  • Security fixes

    • Fixed a security bug in /proxy endpoint that allowed requests to a variation of domains in the allowProxyFor list. If example.com is in allowProxyFor setting, this allowed requests to a domain with a different prefix, like badexample.com to pass through. #212
  • Deprecations

Copy link
Contributor

@peterhassall peterhassall left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@na9da na9da merged commit e6f1b0e into main Dec 4, 2025
6 checks passed
@na9da na9da deleted the rel-044 branch December 4, 2025 02:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants