You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This opens a whole can of worms securitywise, which I'm not sure we can tackle properly (biggest issue being CSRF). Maybe a first step would be adding an allowlist of domains as a config option, so operators of transcribee instances can allow the ones they need. For example, we probably want to allow media.ccc.de which is a relatively trusted source. Would that work for you @moeffju?
I see... requesting internal locations would be bad... Is it feasible to block internal requests and request external locations without authentication? Is a TLD allowlist a sane option?
Instead of uploading a file, it would be great if I could give a URL to download the file from.
The text was updated successfully, but these errors were encountered: