mirror of
https://github.com/superseriousbusiness/gotosocial.git
synced 2025-02-13 17:10:03 +01:00
Disallow cleartext HTTP for Web Push servers
This commit is contained in:
parent
93aeadbd9f
commit
b0d0f8c0c6
@ -225,8 +225,7 @@ func validateNormalizeCreate(request *apimodel.WebPushSubscriptionCreateRequest)
|
||||
if err != nil {
|
||||
return errors.New("endpoint must be a valid URL")
|
||||
}
|
||||
// TODO: (Vyr) remove http option after testing
|
||||
if endpointURL.Scheme != "https" && endpointURL.Scheme != "http" {
|
||||
if endpointURL.Scheme != "https" {
|
||||
return errors.New("endpoint must be an https:// URL")
|
||||
}
|
||||
if endpointURL.Host == "" {
|
||||
|
Loading…
Reference in New Issue
Block a user