mirror of
https://github.com/outbackdingo/firezone.git
synced 2026-01-27 18:18:55 +00:00
Previously, we just assumed that the domain in the query is a subdomain of the resource but a malicious actor can hijack that field to access domains that doesn't correspond to that resource. With this patch we don't even resolve the address for unrelated domains.