From dbd2cb231da05fa5ef0c91f8bdd47444895479ee Mon Sep 17 00:00:00 2001 From: Isaac Connor Date: Fri, 25 Sep 2026 07:56:03 -0400 Subject: [PATCH] fix: refuse cross-site image proxy requests by Sec-Fetch-Site The CSRF token check on the image proxy only runs when ZM_ENABLE_CSRF_MAGIC is on. Browsers that send Sec-Fetch-Site report when another site started a request, so refuse proxy requests whose value is anything but same-origin or none, whatever the CSRF setting. Browsers that do not send the header are unaffected. Co-Authored-By: Claude Opus 5.5 --- web/views/image.php | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/web/views/image.php b/web/views/image.php index 0556d0d0d..e550fc287 100644 --- a/web/views/image.php +++ b/web/views/image.php @@ -74,6 +74,14 @@ if (!empty($_REQUEST['proxy'])) { return; } } + // Also covers installs with CSRF magic off: browsers that send Sec-Fetch-Site + // say when a request was started by another site. Older browsers omit it. + if (isset($_SERVER['HTTP_SEC_FETCH_SITE']) and + !in_array($_SERVER['HTTP_SEC_FETCH_SITE'], ['same-origin', 'none'], true)) { + ZM\Warning('Image proxy request started by another site'); + http_response_code(403); + return; + } $url = $_REQUEST['proxy']; if (!$url) {