KodeStar
881533baa5
Harden against host header injection and open redirect
...
Heimdall trusted the incoming X-Forwarded-Host header for URL generation, so
a spoofed value poisoned the page base href, asset() URLs and redirect
targets - loading assets from and redirecting to an attacker-controlled host
(CVE-2025-50578).
- TrustProxies no longer trusts X-Forwarded-Host; a forged value can no longer
influence getHost(), url(), asset() or redirects. X-Forwarded-For/Port/Proto
handling is unchanged.
- Trusted proxies are now configurable via the TRUSTED_PROXIES env var
(comma-separated CIDRs/IPs, "*" to trust all), defaulting to the previous
private ranges.
- Added an opt-in TRUSTED_HOSTS allow-list: when set, only the listed hosts are
served and any other Host header is rejected. Unset keeps the historic
behaviour of serving arbitrary hosts, so existing installs are unaffected.
Resolves #1451
2026-07-08 14:42:12 +01:00
Shift
b9e75b9284
Remove default app files
2025-07-10 18:53:54 +00:00
Shift
f3a5be79dc
Remove redundant typing from DocBlocks
2024-02-16 21:13:14 +00:00
Shift
2cb837e4b5
Add type hints for Laravel 10
2024-02-16 21:13:13 +00:00
Shift
6423ccd075
Shift core files
2024-02-16 20:33:36 +00:00
Shift
d41c4c8d4c
Replace deprecated HEADER_X_FORWARDED_ALL constant
2024-02-16 20:33:33 +00:00
Shift
aa72ce0a3f
Shift registered middleware
2024-02-16 20:33:32 +00:00
Attila Kerekes
aa886e4f77
fix: Public access to front also applies to tags
2022-12-15 20:17:08 +01:00
Attila Kerekes
5eb1f55b82
chore: Add php code sniffer github check ( #1066 )
2022-12-11 11:58:58 +01:00
Attila Kerekes
52620bc331
chore: Add laravel ide helper
2022-12-01 09:17:54 +00:00
Attila Jozsef Kerekes
7565bd4028
chore: Add php code sniffer and apply fixes
2022-11-25 23:05:58 +00:00
Attila Kerekes
fc2d153ded
fix: Expired session setCookie issue #379
2022-11-16 23:53:34 +01:00
Attila Kerekes
b390a719e9
refactor: apply auto fixes from idea
2022-11-14 14:48:38 +01:00
Kode
fc023401f5
remove heimdall specific xsrf token as clearly not working
2022-06-29 13:13:00 +01:00
Shift
b1dc4d4a41
Apply Laravel coding style
...
Shift automatically applies the Laravel coding style - which uses the PSR-2 coding style as a base with some minor additions.
You may customize the adopted coding style by adding a [PHP CS Fixer][1] or [PHP CodeSniffer][2] config to your project root. Feel free to use [Shift's Laravel ruleset][3] to help you get started.
For more information on customizing the code style applied by Shift, [watch this short video][4].
[1]: https://github.com/FriendsOfPHP/PHP-CS-Fixer
[2]: https://github.com/squizlabs/PHP_CodeSniffer
[3]: https://gist.github.com/laravel-shift/cab527923ed2a109dda047b97d53c200
[4]: https://laravelshift.com/videos/shift-code-style
2022-03-19 13:54:32 +00:00
Kode
06a23c70af
Should fix #379
2022-03-12 13:09:50 +00:00
Chris
ac8fe7012b
remove false from routes
2019-06-18 10:51:51 +01:00
KodeStar
dd2ca62eaf
Add private subnets to trusted proxies for reverse proxy use
2019-06-11 11:00:44 +01:00
Chris
aceed3d13b
fix settings edit not working
2018-10-15 14:35:14 +01:00
Chris
10b70d4a09
changes
2018-10-15 13:02:16 +01:00
Kode
6501aacb1b
update to laravel 5.7 and try getting autologin saved
2018-10-14 20:50:32 +01:00
Chris
482831b9f9
first working(ish) app!
2018-02-08 15:50:53 +00:00
Chris
30aea8e361
updated dependencies + working api connection
2018-02-08 14:21:29 +00:00
KodeStar
83f2a81e91
changes
2018-02-05 19:43:24 +00:00
KodeStar
25bbf6f99a
added order saving, dragging and pinning
2018-02-03 00:22:42 +00:00
Kode
3e1a7119d9
First commit
2018-01-26 14:35:01 +00:00