rinpatch 6ca709816f Fix object spoofing vulnerability in attachments
Validate the content-type of the response when fetching an object,
according to https://www.w3.org/TR/activitypub/#x3-2-retrieving-objects.

content-type headers had to be added to many mocks in order to support
this, some of this was done with a regex. While I did go over the
resulting files to check I didn't modify anything unrelated, there is a
 possibility I missed something.

Closes pleroma#1948
2020-11-12 15:25:33 +03:00
..
2020-10-12 12:00:50 -05:00
2020-04-06 11:13:59 +03:00
2020-03-03 12:21:10 +03:00
2018-02-25 17:48:31 +01:00
2020-09-22 21:58:30 +03:00
2020-08-24 15:01:45 +03:00
2019-07-10 15:23:25 +00:00
2019-04-06 17:18:59 +07:00
2018-02-17 21:56:52 +01:00
2018-03-03 18:38:40 +01:00
2018-05-20 21:01:14 -04:00
2019-05-21 14:12:10 +03:00
2017-04-26 14:25:44 +02:00
2017-04-23 15:21:58 +02:00
2019-05-20 12:58:06 +01:00
2020-08-07 16:03:06 +02:00
2017-04-24 18:46:02 +02:00
2017-04-24 18:46:02 +02:00
2017-04-28 17:41:12 +02:00