You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please refer to #6916 for some background on this functionality.
Making this easily configurable could, as far as I can tell, basically make it possible to modify the HOSTED_VIEWER_ORIGINS list at runtime. Hence that would essentially render the security that this functionality provides useless, since a user could then (easily) modify it to bypass the restrictions set.
Right now you restrict URLs to HOSTED_VIEWER_ORIGINS but there's now easy way to change these as it's a const.
The text was updated successfully, but these errors were encountered: