Skip to content

Prevent TokenOwnershipValidator from leaking info about internal services - #2172

Merged
joachimvh merged 3 commits into
mainfrom
feat/block-token-urls
Jun 18, 2026
Merged

Prevent TokenOwnershipValidator from leaking info about internal services#2172
joachimvh merged 3 commits into
mainfrom
feat/block-token-urls

Conversation

@joachimvh

Copy link
Copy Markdown
Member

✍️ Description

The TokenOwnershipValidator fetches the provided WebID and outputs any errors when doing so. If an internal address is provided as WebID this could potentially leak information about what is running on the server.

This was reported through a security advisory but I didn't get CI working there, so commits got copied here.

@joachimvh

Copy link
Copy Markdown
Member Author

@fortress07 I copied your commits here.

@fortress07

fortress07 commented Jun 17, 2026

Copy link
Copy Markdown

@fortress07 I copied your commits here.

I can see that the commits has passed all the tests.

@joachimvh
joachimvh merged commit 67d9cbd into main Jun 18, 2026
30 checks passed
@joachimvh
joachimvh deleted the feat/block-token-urls branch June 18, 2026 06:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants