PSA: Next version of FreshRSS will have a breaking change for users with feeds in local network (think RSS-Bridge or RSSHub) to improve security
(framapiaf.org)
from BlackEco@lemmy.blackeco.com to selfhosted@lemmy.world on 28 Jun 17:33
https://lemmy.blackeco.com/post/3150747
from BlackEco@lemmy.blackeco.com to selfhosted@lemmy.world on 28 Jun 17:33
https://lemmy.blackeco.com/post/3150747
Breaking change in #FreshRSS for those of you with feeds on your local network such as RSS-Bridge or RSSHub: for improving security (SSRF), local addresses must be added to your allowed list. There are a Web UI and an environment variable INTERNAL_HOST_ALLOWLIST, whichever is easiest. Breaking changes in FreshRSS are rare, but this has been made default since not everybody is able to properly isolate their services. This has just landed in the rolling release (edge). Tests welcome.
#selfhosted
threaded - newest
Thanks.