mirror of
https://github.com/zulip/zulip.git
synced 2025-11-07 23:43:43 +00:00
Providing a signed Camo URL for arbitrary URLs opened the server up to being an open redirector. Return 403 if the URL is not a user upload, and the backend image if it is. Since we do not have ImageAttachment rows for uploads at a time we wrote `/thumbnail?` URLs, return the full-size content.
1.2 KiB
1.2 KiB