Skip to content
Snippets Groups Projects
  1. Apr 30, 2021
  2. Apr 29, 2021
  3. Apr 28, 2021
  4. Apr 27, 2021
  5. Apr 15, 2021
  6. Apr 10, 2021
  7. Apr 07, 2021
  8. Apr 06, 2021
  9. Apr 05, 2021
  10. Apr 03, 2021
    • BlackDex's avatar
      Updated icon fetching. · 1d0eaac2
      BlackDex authored
      - Added image type checking, and prevent downloading non images.
        We didn't checked this before, which could in turn could allow someone
      to download an arbitrary file.
      - This also prevents SVG images from being used, while they work on the
        web-vault and desktop client, they didn't on the mobile versions.
      - Because of this image type checking we can return a valid file type
        instead of only 'x-icon' (which is still used as a fallback).
      - Prevent rel values with `icon-mask`, these are not valid favicons.
      1d0eaac2
  11. Apr 02, 2021
  12. Apr 01, 2021
  13. Mar 31, 2021
  14. Mar 30, 2021
Loading