Pleroma/test/fixtures
rinpatch 6ca709816f Fix object spoofing vulnerability in attachments
Validate the content-type of the response when fetching an object,
according to https://www.w3.org/TR/activitypub/#x3-2-retrieving-objects.

content-type headers had to be added to many mocks in order to support
this, some of this was done with a regex. While I did go over the
resulting files to check I didn't modify anything unrelated, there is a
 possibility I missed something.

Closes pleroma#1948
2020-11-12 15:25:33 +03:00
..
config
emoji/packs
fetch_mocks
modules
preload_static/instance
relay
rich_media
tesla_mock
users_mock
warnings/otp_version
activitypub-client-post-activity.json
avatar_data_uri
bogus-mastodon-announce.json
create-chat-message.json
custom_instance_panel.html
DSCN0010.jpg
emoji-reaction-no-emoji.json
emoji-reaction-too-long.json
emoji-reaction.json
emojis.zip
empty.zip
friendica_salmon.xml
host-meta-zetsubou.xn--q9jyb4c.xml
hubzilla-follow-activity.json
image.gif
image.jpg
image.png
kroeg-announce-with-inline-actor.json
kroeg-array-less-emoji.json
kroeg-array-less-hashtag.json
kroeg-post-activity.json
lain.xml
lambadalambda.json
margaret-corbin-grave-west-point.html
mastodon-accept-activity.json
mastodon-announce-private.json
mastodon-announce.json
mastodon-block-activity.json
mastodon-create-with-attachment.json
mastodon-delete-user.json
mastodon-delete.json
mastodon-follow-activity.json
mastodon-like.json
mastodon-note-object.json
mastodon-post-activity-contentmap.json
mastodon-post-activity-hashtag.json
mastodon-post-activity-nsfw.json
mastodon-post-activity.json
mastodon-question-activity.json
mastodon-reject-activity.json
mastodon-unblock-activity.json
mastodon-undo-announce.json
mastodon-undo-like-compact-object.json
mastodon-undo-like.json
mastodon-unfollow-activity.json
mastodon-update.json
mastodon-vote.json
mewmew_no_name.json
misskey-like.json
nypd-facial-recognition-children-teenagers2.html
nypd-facial-recognition-children-teenagers3.html
nypd-facial-recognition-children-teenagers4.html
nypd-facial-recognition-children-teenagers.html
osada-follow-activity.json
prismo-url-map.json
private_key.pem
rel_me_anchor_nofollow.html
rel_me_anchor.html
rel_me_link.html
rel_me_null.html
salmon2.xml
salmon.xml
sound.mp3
spoofed-object.json Fix object spoofing vulnerability in attachments 2020-11-12 15:25:33 +03:00
test.txt
user_full.xml
user_name_only.xml
webfinger.xml