fix: refuse cross-site image proxy requests by Sec-Fetch-Site

The CSRF token check on the image proxy only runs when ZM_ENABLE_CSRF_MAGIC
is on. Browsers that send Sec-Fetch-Site report when another site started a
request, so refuse proxy requests whose value is anything but same-origin or
none, whatever the CSRF setting. Browsers that do not send the header are
unaffected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Isaac ConnorandClaude Opus 5.5 committed 2026-09-25 07:56:03 -04:00
1 parent 1d5fb76b04
commit dbd2cb231d
1 file changed
+8
+8
View File
@@ -74,6 +74,14 @@ if (!empty($_REQUEST['proxy'])) {
return;
}
}
// Also covers installs with CSRF magic off: browsers that send Sec-Fetch-Site
// say when a request was started by another site. Older browsers omit it.
if (isset($_SERVER['HTTP_SEC_FETCH_SITE']) and
!in_array($_SERVER['HTTP_SEC_FETCH_SITE'], ['same-origin', 'none'], true)) {
ZM\Warning('Image proxy request started by another site');
http_response_code(403);
return;
}
$url = $_REQUEST['proxy'];
if (!$url) {