mirror of
https://github.com/the-djmaze/snappymail.git
synced 2026-08-28 03:29:20 +03:00
Moved Fetch Metadata security due to issues with API and
https://github.com/the-djmaze/snappymail/issues/99#issuecomment-895293750 This should prevent security error on visiting "index" in any way, but keep security on any sub-request
This commit is contained in:
parent
adb5619438
commit
89740bf50f
2 changed files with 17 additions and 14 deletions
|
|
@ -28,16 +28,6 @@ if (!\defined('RAINLOOP_APP_LIBRARIES_PATH'))
|
|||
|
||||
if (\class_exists('RainLoop\Api'))
|
||||
{
|
||||
if (!\SnappyMail\HTTP\SecFetch::isEntering() && !\SnappyMail\HTTP\SecFetch::isSameOrigin()) {
|
||||
\MailSo\Base\Http::StatusHeader(403);
|
||||
exit("Disallowed Sec-Fetch
|
||||
Dest: " . ($_SERVER['HTTP_SEC_FETCH_DEST'] ?? '') . "
|
||||
Mode: " . ($_SERVER['HTTP_SEC_FETCH_MODE'] ?? '') . "
|
||||
Site: " . ($_SERVER['HTTP_SEC_FETCH_SITE'] ?? '') . "
|
||||
User: " . (\SnappyMail\HTTP\SecFetch::user() ? 'true' : 'false')
|
||||
);
|
||||
}
|
||||
|
||||
\MailSo\Base\Loader::Init();
|
||||
|
||||
if (!empty($_ENV['RAINLOOP_INCLUDE_AS_API']))
|
||||
|
|
|
|||
|
|
@ -107,15 +107,26 @@ class Service
|
|||
{
|
||||
\MailSo\Base\Http::StatusHeader(403);
|
||||
echo $this->oServiceActions->ErrorTemplates('Access Denied.',
|
||||
'Access to the SnappyMail Admin Panel is not allowed!', true);
|
||||
'Access to the SnappyMail Admin Panel is not allowed!');
|
||||
|
||||
return $this;
|
||||
return false;
|
||||
}
|
||||
|
||||
$bIndex = true;
|
||||
$sResult = '';
|
||||
if (0 < \count($aPaths) && !empty($aPaths[0]) && !$bAdmin && 'index' !== \strtolower($aPaths[0]))
|
||||
{
|
||||
if (!\SnappyMail\HTTP\SecFetch::isSameOrigin()) {
|
||||
\MailSo\Base\Http::StatusHeader(403);
|
||||
echo $this->oServiceActions->ErrorTemplates('Access Denied.',
|
||||
"Disallowed Sec-Fetch
|
||||
Dest: " . ($_SERVER['HTTP_SEC_FETCH_DEST'] ?? '') . "
|
||||
Mode: " . ($_SERVER['HTTP_SEC_FETCH_MODE'] ?? '') . "
|
||||
Site: " . ($_SERVER['HTTP_SEC_FETCH_SITE'] ?? '') . "
|
||||
User: " . (\SnappyMail\HTTP\SecFetch::user() ? 'true' : 'false'));
|
||||
return false;
|
||||
}
|
||||
|
||||
$bIndex = false;
|
||||
$sMethodName = 'Service'.\preg_replace('/@.+$/', '', $aPaths[0]);
|
||||
$sMethodExtra = 0 < \strpos($aPaths[0], '@') ? \preg_replace('/^[^@]+@/', '', $aPaths[0]) : '';
|
||||
|
|
@ -134,6 +145,7 @@ class Service
|
|||
|
||||
if ($bIndex)
|
||||
{
|
||||
// if (!\SnappyMail\HTTP\SecFetch::isEntering()) {
|
||||
\header('Content-Type: text/html; charset=utf-8');
|
||||
$this->oHttp->ServerNoCache();
|
||||
|
||||
|
|
@ -141,10 +153,10 @@ class Service
|
|||
{
|
||||
echo $this->oServiceActions->ErrorTemplates(
|
||||
'Permission denied!',
|
||||
'SnappyMail cannot access to the data folder "'.APP_DATA_FOLDER_PATH.'"'
|
||||
'SnappyMail can not access the data folder "'.APP_DATA_FOLDER_PATH.'"'
|
||||
);
|
||||
|
||||
return $this;
|
||||
return false;
|
||||
}
|
||||
|
||||
$sLanguage = $this->oActions->GetLanguage($bAdmin);
|
||||
|
|
@ -204,6 +216,7 @@ class Service
|
|||
}
|
||||
// Internet Explorer does not support 'nonce'
|
||||
if (!\strpos($_SERVER['HTTP_USER_AGENT'], 'Trident/') && !\strpos($_SERVER['HTTP_USER_AGENT'], 'Edge/1')) {
|
||||
// Knockout.js requires unsafe-inline?
|
||||
if ($sScriptNonce) {
|
||||
$sContentSecurityPolicy = \preg_replace("/(script-src[^;]+)'unsafe-inline'/", "\$1'nonce-{$sScriptNonce}'", $sContentSecurityPolicy);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue