Further limit HTTP fetching security from Openfire

Description

https://github.com/igniterealtime/Openfire/pull/1497#issuecomment-538382149

Having pondered, I worry that even if we're not displaying it, the admin console will happily fetch any file off any HTTP server it has access to. If it were me, I'd probably lean towards changing the way this works such that the servlet
(a) Only fetches favicon's from S2S connected servers, and
(b) Only fetches the favicon

Environment

None

is related to

Activity

Show:
Fixed

Details

Assignee

Reporter

Components

Fix versions

Affects versions

Priority

Created October 27, 2019 at 1:26 AM
Updated November 21, 2019 at 4:11 PM
Resolved November 21, 2019 at 4:11 PM