You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
roundcubemail/program
Felix Eckhofer ef721fc430 Add config variable 'proxy_whitelist'
HTTP headers X_FORWARDED_* and X_REAL_IP are only evaluated when
received from an IP listed in proxy_whitelist. Furthermore, only the
last non-trusted IP from X-Forwarded-For is used in place of the real
ip.

Without this, an attacker can easily spoof the headers and control the
result of the ip or ssl check.

This fixes several problems with [3a4c9f42], [4d480b36] and [a520f331] as
mentioned in #1489729.
11 years ago
..
include Make sure parent folder selector always contains parent folder 11 years ago
js Disable link registering mailto: protocol handler if not supported by the browser (#1489569) 11 years ago
lib Add config variable 'proxy_whitelist' 11 years ago
localization Synchrnonized translations from Transifex 11 years ago
resources Fix browser warnings on PDF plugin detection (#1489118) 12 years ago
steps Make sure parent folder selector always contains parent folder 11 years ago