This repository was archived by the owner on Apr 26, 2024. It is now read-only.
This repository was archived by the owner on Apr 26, 2024. It is now read-only.
Use federation blacklist for requests to identity servers #5935
Closed
Description
Now that we're getting rid of the concept of trusted identity servers, we need to make sure that people can't try and poke at internal addresses when sending identity server-related requests.
The plan is to reuse the federation blacklist for these requests which by default blocks internal CIDR ranges.