summaryrefslogtreecommitdiffstats
path: root/src/invidious.cr
diff options
context:
space:
mode:
Diffstat (limited to 'src/invidious.cr')
-rw-r--r--src/invidious.cr15
1 files changed, 0 insertions, 15 deletions
diff --git a/src/invidious.cr b/src/invidious.cr
index 6a32736c..433c84c7 100644
--- a/src/invidious.cr
+++ b/src/invidious.cr
@@ -106,21 +106,6 @@ spawn do
end
before_all do |env|
- env.response.headers["X-XSS-Protection"] = "1; mode=block;"
- env.response.headers["X-Content-Type-Options"] = "nosniff"
-
- # CSRF
- if Kemal.config.ssl || CONFIG.https_only
- host = env.request.headers["Host"]?
-
- if (env.request.headers["Origin"]?.try &.== host) ||
- (env.request.headers["Referer"]?.try &.== host)
- # All good!
- else
- halt env, status_code: 403, response: "Failed CSRF check"
- end
- end
-
if env.request.cookies.has_key? "SID"
headers = HTTP::Headers.new
headers["Cookie"] = env.request.headers["Cookie"]