]> git.mxchange.org Git - friendica.git/commitdiff
Added host check on xrd request
authorS. Brusch <ne20002@gmx.ch>
Sat, 6 May 2023 15:57:12 +0000 (17:57 +0200)
committerS. Brusch <ne20002@gmx.ch>
Sat, 6 May 2023 20:26:37 +0000 (22:26 +0200)
src/Module/Xrd.php

index 21cff563468d5496f825b7adbf46d7080dac5786..6a4c0e860d31be4c12b07e005074a705d3647ba8 100644 (file)
@@ -65,13 +65,19 @@ class Xrd extends BaseModule
 
                if (substr($uri, 0, 4) === 'http') {
                        $name = ltrim(basename($uri), '~');
+                       $host = parse_url($uri, PHP_URL_HOST);
                } else {
                        $local = str_replace('acct:', '', $uri);
                        if (substr($local, 0, 2) == '//') {
                                $local = substr($local, 2);
                        }
 
-                       $name = substr($local, 0, strpos($local, '@'));
+                       list($name, $host) = explode('@', $local);
+               }
+
+               if (!empty($host) && $host !== DI::baseUrl()->getHost()) {
+                       DI::logger()->notice('Invalid host name for xrd query',['host' => $host, 'uri' => $uri]);
+                       throw new NotFoundException('Invalid host name for xrd query: ' . $host);
                }
 
                if ($name == User::getActorName()) {