[Bugfix] Improve OPML route security (#535)
* WIP - moved plugs; set up a new token-protected route plug * Added a route_token column to settings model * Hooked up token_protected_route plug to database * Hooked up new OPML route to UI; turned RSS and OPML feed buttons into links * Docs, tests * Added a note about the phoenix bug
This commit is contained in:
@@ -73,6 +73,13 @@ defmodule PinchflatWeb.Endpoint do
|
||||
Phoenix.Controller.put_router_url(conn, new_base_url)
|
||||
end
|
||||
|
||||
# Some podcast clients require file extensions, and others still will _add_
|
||||
# file extensions to XML files if they don't have them. This plug removes
|
||||
# the extension from the path so that the correct route is matched, regardless
|
||||
# of the provided extension.
|
||||
#
|
||||
# This has the downside of in-app generated verified routes not working with
|
||||
# extensions so this behaviour may change in the future.
|
||||
defp strip_trailing_extension(%{path_info: []} = conn, _opts), do: conn
|
||||
|
||||
defp strip_trailing_extension(conn, _opts) do
|
||||
|
||||
Reference in New Issue
Block a user