subidx/.gitignore
lakshit verma 9a232a950c
server: reject unexpected Host headers to block DNS rebinding
The API accepted any Host header, so a page running a DNS rebinding
attack could point attacker.com at 127.0.0.1 and read the collected
index from the victim's browser as same-origin JavaScript. Requests
whose Host is not localhost/127.0.0.1/::1 now get 421; -allowed-hosts
extends the list for exposed deployments. Rate limiting keyed on the
victim's own IP provided no protection here.
2026-08-22 03:44:43 +05:30

5 lines
36 B
Text

/subidx
/data/
*.log
SPEC.md
/docs/