Invision Community 4: SEO, prepare for v5 and dormant account notifications By Matt Monday at 02:04 PM
DawPi Posted September 14, 2020 Posted September 14, 2020 Nope. Due to security reason. The same situation with remote images and serving them from local.
bfarber Posted September 15, 2020 Posted September 15, 2020 Allowing your server to fetch arbitrary remote content from user-supplied URLs opens the site up to SSRF security concerns. We mitigated around these concerns but decided in this day and age, the cat and mouse game is really no longer necessary or "worth it".
Square Wheels Posted September 15, 2020 Author Posted September 15, 2020 1 minute ago, bfarber said: Allowing your server to fetch arbitrary remote content from user-supplied URLs opens the site up to SSRF security concerns. We mitigated around these concerns but decided in this day and age, the cat and mouse game is really no longer necessary or "worth it". Fair enough. Thanks for the explanation.
Recommended Posts