1
0
дзеркало https://github.com/therootcompany/greenlock.js.git synced 2024-11-16 17:29:00 +00:00

Порівняти коміти

..

2 Коміти

Автор SHA1 Повідомлення Дата
2cfba7a2e7 v2.4.1 disallow domain fronting 2018-08-22 15:49:32 -06:00
ea02a93fba v2.4.0 bump version for easy identification of latest security features 2018-08-22 14:17:51 -06:00
2 змінених файлів з 18 додано та 1 видалено

@ -517,10 +517,27 @@ Greenlock.create = function (gl) {
req.headers.host = host.join(':');
}
if (gl.__sni_allow_fronting) {
if (req.socket && 'string' === typeof req.socket.servername) {
if (safehost && (safehost !== req.socket.servername.toLowerCase())) {
res.statusCode = 400;
res.end("Don't be frontin', yo!"
+ " TLS SNI '" + req.socket.servername.toLowerCase() + "' does not match 'Host: " + safehost + "'");
return;
}
} else if (safehost && !gl.middleware.sanitizeHost._skip_fronting_check) {
// TODO how to handle wrapped sockets, as with telebit?
console.warn("\n\n\n[greenlock] WARN: no string for req.socket.servername,"
+ " skipping fronting check for '" + safehost + "'\n\n\n");
gl.middleware.sanitizeHost._skip_fronting_check = true;
}
}
// carry on
realNext();
};
};
gl.middleware.sanitizeHost._skip_fronting_check = false;
return gl;
};

@ -1,6 +1,6 @@
{
"name": "greenlock",
"version": "2.3.13",
"version": "2.4.1",
"description": "Let's Encrypt for node.js on npm",
"main": "index.js",
"files": [