HoneyryderChuck ffb24f71c6 remove authorization header when redirecting to different-origin urls
this is an old vuln fixed in curl (https://github.com/advisories/GHSA-7xmh-mw7w-rr97), which has been fixed for a long time, where credentials via authorization header would be resent on all follow location requests; this limits it to same-origin redirects; an option, "auth_to_other_origins", can be used to keep original behaviour
2023-11-17 15:16:52 +00:00
..
2023-08-16 01:08:41 +01:00
2023-10-12 22:39:26 +01:00
2023-09-20 17:57:39 +01:00
2020-10-30 16:19:18 +00:00