diff options
author | Gannon McGibbon <gannon.mcgibbon@gmail.com> | 2019-01-22 11:40:13 -0500 |
---|---|---|
committer | Gannon McGibbon <gannon.mcgibbon@gmail.com> | 2019-01-22 11:40:13 -0500 |
commit | 2e0ca9284a6864cfbbb632d849df3fdd7a7c554e (patch) | |
tree | bae8c7bdbdf70dd05a506527f2724ddf4ec1dad7 /activestorage/app/controllers/active_storage | |
parent | e26f0658da7ff7e9382d6040fe76c087ff1791e4 (diff) | |
download | rails-2e0ca9284a6864cfbbb632d849df3fdd7a7c554e.tar.gz rails-2e0ca9284a6864cfbbb632d849df3fdd7a7c554e.tar.bz2 rails-2e0ca9284a6864cfbbb632d849df3fdd7a7c554e.zip |
Revert ensure external redirects are explicitly allowed
Diffstat (limited to 'activestorage/app/controllers/active_storage')
-rw-r--r-- | activestorage/app/controllers/active_storage/blobs_controller.rb | 2 | ||||
-rw-r--r-- | activestorage/app/controllers/active_storage/representations_controller.rb | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/activestorage/app/controllers/active_storage/blobs_controller.rb b/activestorage/app/controllers/active_storage/blobs_controller.rb index a8e42d7356..4fc3fbe824 100644 --- a/activestorage/app/controllers/active_storage/blobs_controller.rb +++ b/activestorage/app/controllers/active_storage/blobs_controller.rb @@ -9,6 +9,6 @@ class ActiveStorage::BlobsController < ActiveStorage::BaseController def show expires_in ActiveStorage.service_urls_expire_in - redirect_to @blob.service_url(disposition: params[:disposition]), allow_other_host: true + redirect_to @blob.service_url(disposition: params[:disposition]) end end diff --git a/activestorage/app/controllers/active_storage/representations_controller.rb b/activestorage/app/controllers/active_storage/representations_controller.rb index d01af5d939..98e11e5dbb 100644 --- a/activestorage/app/controllers/active_storage/representations_controller.rb +++ b/activestorage/app/controllers/active_storage/representations_controller.rb @@ -9,6 +9,6 @@ class ActiveStorage::RepresentationsController < ActiveStorage::BaseController def show expires_in ActiveStorage.service_urls_expire_in - redirect_to @blob.representation(params[:variation_key]).processed.service_url(disposition: params[:disposition]), allow_other_host: true + redirect_to @blob.representation(params[:variation_key]).processed.service_url(disposition: params[:disposition]) end end |