aboutsummaryrefslogtreecommitdiff
path: root/IkiWiki.pm
diff options
context:
space:
mode:
authorSimon McVittie <smcv@debian.org>2019-02-10 16:30:07 +0000
committerSimon McVittie <smcv@debian.org>2019-02-26 21:44:07 +0000
commit67543ce1d62161fdef9dca198289d7dd7dceacc0 (patch)
treec38827ad186714a95d8cc27d2636a2fe031949ab /IkiWiki.pm
parente7b0d4a0fff8ed45a90c2efe8ef294bdf7c9bdac (diff)
downloadikiwiki-67543ce1d62161fdef9dca198289d7dd7dceacc0.tar
ikiwiki-67543ce1d62161fdef9dca198289d7dd7dceacc0.tar.gz
useragent: Don't allow non-HTTP protocols to be used
This prevents the aggregate plugin from being used to read the contents of local files via file:/// URLs. Signed-off-by: Simon McVittie <smcv@debian.org>
Diffstat (limited to 'IkiWiki.pm')
-rw-r--r--IkiWiki.pm1
1 files changed, 1 insertions, 0 deletions
diff --git a/IkiWiki.pm b/IkiWiki.pm
index dc047b08a..d5d1af56c 100644
--- a/IkiWiki.pm
+++ b/IkiWiki.pm
@@ -2477,6 +2477,7 @@ sub useragent () {
cookie_jar => $config{cookiejar},
env_proxy => 1, # respect proxy env vars
agent => $config{useragent},
+ protocols_allowed => [qw(http https)],
);
}