Files
zoneminder/web/views
Isaac ConnorandClaude Opus 5.5 dbd2cb231d fix: refuse cross-site image proxy requests by Sec-Fetch-Site
The CSRF token check on the image proxy only runs when ZM_ENABLE_CSRF_MAGIC
is on. Browsers that send Sec-Fetch-Site report when another site started a
request, so refuse proxy requests whose value is anything but same-origin or
none, whatever the CSRF setting. Browsers that do not send the header are
unaffected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 07:56:03 -04:00
..
2021-08-18 10:53:59 -04:00
2021-10-14 17:56:16 -04:00