* Don't allow URLs that contain non-normalized paths to be verified This stops things like https://example.com/otheruser/../realuser where "/otheruser" appears to be the verified URL, but the actual URL being verified is "/realuser" due to the "/../". Also fix a test to use 'https', so it is testing the right thing, now that since #20304 https is required. * missing do |
||
|---|---|---|
| .. | ||
| config/initializers | ||
| controllers | ||
| fabricators | ||
| features | ||
| fixtures | ||
| helpers | ||
| lib | ||
| mailers | ||
| models | ||
| policies | ||
| presenters | ||
| requests | ||
| routing | ||
| serializers/activitypub | ||
| services | ||
| support | ||
| validators | ||
| views/statuses | ||
| workers | ||
| rails_helper.rb | ||
| spec_helper.rb | ||