Revert "Add Origin header checks"

This reverts commit 2be240767c.
This commit is contained in:
Omar Roth 2018-11-07 23:13:51 -06:00
parent 2be240767c
commit f988123820
2 changed files with 0 additions and 10 deletions

View file

@ -128,15 +128,6 @@ if CONFIG.geo_bypass
end end
before_all do |env| before_all do |env|
if CONFIG.domains && env.request.headers["Origin"]?
origin = env.request.headers["Origin"]
domains = CONFIG.domains.not_nil!
if !domains.includes? origin
halt env, status_code: 403
end
end
env.response.headers["X-XSS-Protection"] = "1; mode=block;" env.response.headers["X-XSS-Protection"] = "1; mode=block;"
env.response.headers["X-Content-Type-Options"] = "nosniff" env.response.headers["X-Content-Type-Options"] = "nosniff"

View file

@ -16,7 +16,6 @@ class Config
hmac_key: String?, hmac_key: String?,
full_refresh: Bool, full_refresh: Bool,
geo_bypass: Bool, geo_bypass: Bool,
domains: Array(String)?,
}) })
end end