summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
authorOmar Roth <omarroth@hotmail.com>2018-11-07 23:13:51 -0600
committerOmar Roth <omarroth@hotmail.com>2018-11-07 23:13:51 -0600
commitf98812382091c0ab12f4981c803c532f59f0c911 (patch)
tree1f371bceeeec342bf1c3d0ac0095291ddd01d578 /src
parent2be240767c65a17e563fc80a389ac4e568c47d41 (diff)
downloadinvidious-f98812382091c0ab12f4981c803c532f59f0c911.tar.gz
invidious-f98812382091c0ab12f4981c803c532f59f0c911.tar.bz2
invidious-f98812382091c0ab12f4981c803c532f59f0c911.zip
Revert "Add Origin header checks"
This reverts commit 2be240767c65a17e563fc80a389ac4e568c47d41.
Diffstat (limited to 'src')
-rw-r--r--src/invidious.cr9
-rw-r--r--src/invidious/helpers/helpers.cr1
2 files changed, 0 insertions, 10 deletions
diff --git a/src/invidious.cr b/src/invidious.cr
index d8c7301e..3c251d96 100644
--- a/src/invidious.cr
+++ b/src/invidious.cr
@@ -128,15 +128,6 @@ if CONFIG.geo_bypass
end
before_all do |env|
- if CONFIG.domains && env.request.headers["Origin"]?
- origin = env.request.headers["Origin"]
- domains = CONFIG.domains.not_nil!
-
- if !domains.includes? origin
- halt env, status_code: 403
- end
- end
-
env.response.headers["X-XSS-Protection"] = "1; mode=block;"
env.response.headers["X-Content-Type-Options"] = "nosniff"
diff --git a/src/invidious/helpers/helpers.cr b/src/invidious/helpers/helpers.cr
index 98357440..92a2e1b1 100644
--- a/src/invidious/helpers/helpers.cr
+++ b/src/invidious/helpers/helpers.cr
@@ -16,7 +16,6 @@ class Config
hmac_key: String?,
full_refresh: Bool,
geo_bypass: Bool,
- domains: Array(String)?,
})
end