mirror of
https://github.com/TryGhost/Ghost.git
synced 2025-03-11 02:12:21 -05:00
no issue - prevent oembed fetching from accessing IP addresses or localhost domains - prevent oembed endpoint from passing through fetched responses as-is - reject any fetched data that does not validate against the oembed spec - strip any unknown properties from the oembed response before returning Credits: Nick Mykhailyshyn |
||
---|---|---|
.. | ||
adapters | ||
api | ||
config | ||
data | ||
lib | ||
models | ||
public | ||
services | ||
translations | ||
views | ||
web | ||
analytics-events.js | ||
ghost-server.js | ||
index.js | ||
overrides.js | ||
sentry.js | ||
update-check.js |