mirror of
https://github.com/linuxserver/Heimdall.git
synced 2026-08-07 07:16:13 +00:00
881533baa5
Heimdall trusted the incoming X-Forwarded-Host header for URL generation, so a spoofed value poisoned the page base href, asset() URLs and redirect targets - loading assets from and redirecting to an attacker-controlled host (CVE-2025-50578). - TrustProxies no longer trusts X-Forwarded-Host; a forged value can no longer influence getHost(), url(), asset() or redirects. X-Forwarded-For/Port/Proto handling is unchanged. - Trusted proxies are now configurable via the TRUSTED_PROXIES env var (comma-separated CIDRs/IPs, "*" to trust all), defaulting to the previous private ranges. - Added an opt-in TRUSTED_HOSTS allow-list: when set, only the listed hosts are served and any other Host header is rejected. Unset keeps the historic behaviour of serving arbitrary hosts, so existing installs are unaffected. Resolves #1451
42 lines
1.1 KiB
PHP
42 lines
1.1 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Middleware;
|
|
|
|
use Illuminate\Http\Middleware\TrustHosts as Middleware;
|
|
|
|
class TrustHosts extends Middleware
|
|
{
|
|
/**
|
|
* Get the host patterns that should be trusted.
|
|
*
|
|
* The allow-list is read from the TRUSTED_HOSTS env var (comma-separated
|
|
* hostnames). When it is unset/empty an empty array is returned so that NO
|
|
* host restriction is applied, preserving Heimdall's historic behaviour of
|
|
* running on arbitrary hosts. When set, only the listed hosts (and their
|
|
* subdomains) are accepted; any other Host header is rejected by Symfony
|
|
* with a SuspiciousOperationException (HTTP 400).
|
|
*
|
|
* @return array
|
|
*/
|
|
public function hosts()
|
|
{
|
|
$trustedHosts = env('TRUSTED_HOSTS');
|
|
|
|
if ($trustedHosts === null || trim((string) $trustedHosts) === '') {
|
|
return [];
|
|
}
|
|
|
|
$hosts = [];
|
|
|
|
foreach (explode(',', (string) $trustedHosts) as $host) {
|
|
$host = trim($host);
|
|
|
|
if ($host !== '') {
|
|
$hosts[] = '^(.+\.)?'.preg_quote($host).'$';
|
|
}
|
|
}
|
|
|
|
return $hosts;
|
|
}
|
|
}
|