Files
firezone/rust
Gabi afb989ced9 security(connlib): Dont allow acces to non-subdomains for a given resource (#2996)
Previously, we just assumed that the domain in the query is a subdomain
of the resource but a malicious actor can hijack that field to access
domains that doesn't correspond to that resource.

With this patch we don't even resolve the address for unrelated domains.
2023-12-22 17:42:32 +00:00
..
2023-12-19 15:38:27 -06:00
2023-05-10 07:58:32 -07:00
2023-10-27 13:10:36 -06:00