Skip to content
Snippets Groups Projects
Quentin Duchemin's avatar
Quentin Duchemin authored
Tool is only accessible with the container's network, to avoid potential spam/DOS.
Indeed, one could just call the container's public URL with a forged request to redirect POST requests to an arbitrary server.
With this modification, one could still use Filter Hook with an arbitrary URL, but the call should come from Wekan (i.e. mass move/create cards), which is not worth it.
b9a39e56
History