Skip to content

Conversation

@flyingOwl
Copy link
Contributor

Every server configuration has its own setting that enables the use of
insecure connections. This is disabled by default. Only verified https
connections are allowed. Error messages with a note about the setting
have been added.

CVE-2018-1000664

Discussed in #60

The second commit replaces the http-only subsonic.org demo server with the Navidrome demo server.

Every server configuration has its own setting that enables the use of
insecure connections. This is disabled by default. Only verified https
connections are allowed. Error messages with a note about the setting
have been added.

CVE-2018-1000664

Discussed in daneren2005#60
Replace subsonic.org demo server with navidrome.org demo server as the
latter one uses a secure https connection. Enabling insecure connections
by default to use the subsonic.org demo server would contradict the
concept of "security by default".
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant