Skip to content
Snippets Groups Projects
Select Git revision
  • move-gl-dropdown
  • improve-table-pagination-spec
  • move-markdown-preview
  • winh-fix-merge-request-spec
  • master default
  • index-namespaces-lower-name
  • winh-single-karma-test
  • 10-3-stable
  • 36782-replace-team-user-role-with-add_role-user-in-specs
  • winh-modal-internal-state
  • tz-ide-file-icons
  • 38869-milestone-select
  • update-autodevops-template
  • jivl-activate-repo-cookie-preferences
  • qa-add-deploy-key
  • docs-move-article-ldap
  • 40780-choose-file
  • 22643-manual-job-page
  • refactor-cluster-show-page-conservative
  • dm-sidekiq-versioning
  • v10.4.0.pre
  • v10.3.0
  • v10.3.0-rc5
  • v10.3.0-rc4
  • v10.3.0-rc3
  • v10.3.0-rc2
  • v10.2.5
  • v10.3.0-rc1
  • v10.0.7
  • v10.1.5
  • v10.2.4
  • v10.2.3
  • v10.2.2
  • v10.2.1
  • v10.3.0.pre
  • v10.2.0
  • v10.2.0-rc4
  • v10.2.0-rc3
  • v10.1.4
  • v10.2.0-rc2
40 results

gfm

  • Clone with SSH
  • Clone with HTTPS
  • Forked from GitLab.org / GitLab FOSS
    Source project has a limited visibility.
    Jacob Vosmaer's avatar
    Jacob Vosmaer (GitLab) authored
    Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/17877 .
    
    This change adds 'defense in depth' against 'Host' HTTP header
    injection. It affects normal users in the following way. Suppose your
    GitLab server has IP address 1.2.3.4 and hostname gitlab.example.com.
    Currently, if you enter 1.2.3.4 in your browser, you get redirected to
    1.2.3.4/users/sign_in. After this change, you get redirected from
    1.2.3.4 to gitlab.example.com/users/sign_in. This is because the
    address you typed in the address bar of your browser ('1.2.3.4'),
    which gets stored in the 'Host' header, is now being overwritten to
    'gitlab.example.com' in NGINX.
    
    In this change we also make NGINX clear the 'X-Forwarded-Host' header
    because Ruby on Rails also uses that header the same wayas the 'Host'
    header.
    
    We think that for most GitLab servers this is the right behavior, and
    if not then administrators can change this behavior themselves at the
    NGINX level.
    47b5b441
    History
    Name Last commit Last update
    ..