Skip to content

Conversation

@gpressutto5
Copy link
Contributor

@gpressutto5 gpressutto5 commented Mar 13, 2017

This pull request prevents us from using file_get_contents on an external url, which requires the merchant server to have the allow_url_fopen enabled. This is security liability.
Some hosts don't even allow the setting to be changed, requiring lengthy phone calls.
This pull also removes the full url construct from our boleto iframe to prevent xss.

@gpressutto5 gpressutto5 changed the base branch from master to develop March 13, 2017 14:44
Copy link
Contributor

@SparK-Cruz SparK-Cruz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LG™

@gpressutto5 gpressutto5 merged commit 55b2164 into develop Mar 13, 2017
@gpressutto5 gpressutto5 deleted the feature/get-banking-ticket-by-curl branch March 13, 2017 16:34
@SparK-Cruz SparK-Cruz mentioned this pull request Mar 13, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants