diff options
author | Chocobozzz <me@florianbigard.com> | 2020-11-12 10:42:25 +0100 |
---|---|---|
committer | Chocobozzz <me@florianbigard.com> | 2020-11-12 16:29:32 +0100 |
commit | 797d05bdd99b63104522051d0f61f1e0f003e780 (patch) | |
tree | a0e356958e03aa62c4539afacbf7715eba305954 /server/initializers | |
parent | 2a9562fc5894509e63016b1fe09f6dce0c4b6e5e (diff) | |
download | PeerTube-797d05bdd99b63104522051d0f61f1e0f003e780.tar.gz PeerTube-797d05bdd99b63104522051d0f61f1e0f003e780.tar.zst PeerTube-797d05bdd99b63104522051d0f61f1e0f003e780.zip |
Force signed headers in http signatures
Thanks Roger
Diffstat (limited to 'server/initializers')
-rw-r--r-- | server/initializers/constants.ts | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/server/initializers/constants.ts b/server/initializers/constants.ts index 501e06396..679503731 100644 --- a/server/initializers/constants.ts +++ b/server/initializers/constants.ts | |||
@@ -513,6 +513,10 @@ const HTTP_SIGNATURE = { | |||
513 | HEADER_NAME: 'signature', | 513 | HEADER_NAME: 'signature', |
514 | ALGORITHM: 'rsa-sha256', | 514 | ALGORITHM: 'rsa-sha256', |
515 | HEADERS_TO_SIGN: [ '(request-target)', 'host', 'date', 'digest' ], | 515 | HEADERS_TO_SIGN: [ '(request-target)', 'host', 'date', 'digest' ], |
516 | REQUIRED_HEADERS: { | ||
517 | ALL: [ '(request-target)', 'host', 'date' ], | ||
518 | POST: [ '(request-target)', 'host', 'date', 'digest' ] | ||
519 | }, | ||
516 | CLOCK_SKEW_SECONDS: 1800 | 520 | CLOCK_SKEW_SECONDS: 1800 |
517 | } | 521 | } |
518 | 522 | ||