As gluon-web uses standard multipart/form-data requests, browsers don't
enforce any cross-origin restrictions. To prevent malicious injection of
POST requests into the config mode, match the Origin header against the
Host header of the request.
(cherry picked from commit
|
||
|---|---|---|
| .. | ||
| http | ||
| cgi.lua | ||
| dispatcher.lua | ||
| http.lua | ||
| i18n.lua | ||
| template.lua | ||
| util.lua | ||