User info is not stripped when subscribing to streams. #5

Closed
opened 2025-04-05 09:39:07 -04:00 by LogalDeveloper · 0 comments

If user info is included in a URL supplied by a user, it isn't stripped out. This can allow subscription to the same stream multiple times. This has occurred in the wild and likely happens when a user copies the Fediverse tag of an instance rather than just the domain.

image.png

If user info is included in a URL supplied by a user, it isn't stripped out. This can allow subscription to the same stream multiple times. This has occurred in the wild and likely happens when a user copies the Fediverse tag of an instance rather than just the domain. ![image.png](/attachments/89232e21-ed42-4545-b1eb-cb2fbee3911f)
LogalDeveloper added the Bug label 2025-04-05 09:39:07 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: LogalDeveloper/OwncastSentry#5