@adiz It appears only pleroma+forks are affected. Not that there aren't other zerodays or attack vectors for the other softwares.
@james @dcc @adiz https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy
Headers that prevent media from behaving a certain way in the browser.
@splitshockvirus
So what's this fuss is all about? I don't use media proxy and my Pleroma user doesn't even have admin access. Do I have anything to worry about?
@theorytoe @dcc @james @adiz
@splitshockvirus @theorytoe @dcc @james @adiz
Well, this one looks like a good enough guide: https://arachnid.town/objects/cb0605dd-fe69-4ec7-a6a3-9f9c2515f326
I still don't get why do I have to reconfigure Pleroma to use the subdomain to uploads and mediaproxy if I set up a redirect, but did that anyway 🤷