0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 04:48:33 +08:00
discourse/lib/middleware
Mark VanLandingham db632fd444
SECURITY: Partition anonymous cache keys by Referer for embed routes (#42367)
## Summary

Prevent anonymous cache poisoning on embed routes by incorporating a
SHA-256 digest of the Referer header into the cache key for `/embed/`
requests. This ensures cached responses, which reflect the request
origin in the response body, are correctly partitioned by source domain.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1187

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>
2026-08-05 12:50:55 -05:00
..
anonymous_cache.rb SECURITY: Partition anonymous cache keys by Referer for embed routes (#42367) 2026-08-05 12:50:55 -05:00
crawler_hooks.rb UX: Prevent incomplete crawler localization settings (#41297) 2026-07-01 12:13:22 +08:00
csp_script_nonce_injector.rb PERF: Avoid replacing CSP nonces in non-cacheable responses (#42008) 2026-07-24 09:49:01 +08:00
default_headers.rb
discourse_public_exceptions.rb
enforce_hostname.rb
missing_avatars.rb DEV: Enable Rails/FilePath rubocop rule (#40097) 2026-05-19 19:07:54 +02:00
omniauth_bypass_middleware.rb
overload_protections.rb FIX: Include API key requests in overload protection bypass (#39702) 2026-05-07 12:59:11 +08:00
processing_request.rb PERF: Reject anonymous requests with 503 upon aggressive queuing (#36519) 2025-12-18 10:23:42 +08:00
request_tracker.rb FIX: Rate limit health check requests per backend 2026-07-30 13:36:14 +00:00
track_view_session_id_injector.rb FIX: Anon pageview session id reused across cached responses (#39879) 2026-05-12 10:13:05 +08:00