diff options
| author | Omar Roth <omarroth@hotmail.com> | 2018-11-07 23:13:51 -0600 |
|---|---|---|
| committer | Omar Roth <omarroth@hotmail.com> | 2018-11-07 23:13:51 -0600 |
| commit | f98812382091c0ab12f4981c803c532f59f0c911 (patch) | |
| tree | 1f371bceeeec342bf1c3d0ac0095291ddd01d578 /src | |
| parent | 2be240767c65a17e563fc80a389ac4e568c47d41 (diff) | |
| download | invidious-f98812382091c0ab12f4981c803c532f59f0c911.tar.gz invidious-f98812382091c0ab12f4981c803c532f59f0c911.tar.bz2 invidious-f98812382091c0ab12f4981c803c532f59f0c911.zip | |
Revert "Add Origin header checks"
This reverts commit 2be240767c65a17e563fc80a389ac4e568c47d41.
Diffstat (limited to 'src')
| -rw-r--r-- | src/invidious.cr | 9 | ||||
| -rw-r--r-- | src/invidious/helpers/helpers.cr | 1 |
2 files changed, 0 insertions, 10 deletions
diff --git a/src/invidious.cr b/src/invidious.cr index d8c7301e..3c251d96 100644 --- a/src/invidious.cr +++ b/src/invidious.cr @@ -128,15 +128,6 @@ if CONFIG.geo_bypass end before_all do |env| - if CONFIG.domains && env.request.headers["Origin"]? - origin = env.request.headers["Origin"] - domains = CONFIG.domains.not_nil! - - if !domains.includes? origin - halt env, status_code: 403 - end - end - env.response.headers["X-XSS-Protection"] = "1; mode=block;" env.response.headers["X-Content-Type-Options"] = "nosniff" diff --git a/src/invidious/helpers/helpers.cr b/src/invidious/helpers/helpers.cr index 98357440..92a2e1b1 100644 --- a/src/invidious/helpers/helpers.cr +++ b/src/invidious/helpers/helpers.cr @@ -16,7 +16,6 @@ class Config hmac_key: String?, full_refresh: Bool, geo_bypass: Bool, - domains: Array(String)?, }) end |
