mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 07:25:02 -04:00
fix: refuse cross-site image proxy requests by Sec-Fetch-Site
The CSRF token check on the image proxy only runs when ZM_ENABLE_CSRF_MAGIC is on. Browsers that send Sec-Fetch-Site report when another site started a request, so refuse proxy requests whose value is anything but same-origin or none, whatever the CSRF setting. Browsers that do not send the header are unaffected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
1d5fb76b04
commit
dbd2cb231d
1 file changed
+8
@@ -74,6 +74,14 @@ if (!empty($_REQUEST['proxy'])) {
|
||||
return;
|
||||
}
|
||||
}
|
||||
// Also covers installs with CSRF magic off: browsers that send Sec-Fetch-Site
|
||||
// say when a request was started by another site. Older browsers omit it.
|
||||
if (isset($_SERVER['HTTP_SEC_FETCH_SITE']) and
|
||||
!in_array($_SERVER['HTTP_SEC_FETCH_SITE'], ['same-origin', 'none'], true)) {
|
||||
ZM\Warning('Image proxy request started by another site');
|
||||
http_response_code(403);
|
||||
return;
|
||||
}
|
||||
|
||||
$url = $_REQUEST['proxy'];
|
||||
if (!$url) {
|
||||
|
||||
Reference in new issue
Block a user