Merge pull request from GHSA-3fjr-858r-92rw

* Fix insufficient origin validation

* Bump version to v3.5.17
This commit is contained in:
Claire 2024-02-01 15:56:46 +01:00 committed by GitHub
commit b1ed009c65
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
17 changed files with 46 additions and 43 deletions

View file

@ -157,8 +157,8 @@ module JsonLdHelper
end
end
def fetch_resource(uri, id, on_behalf_of = nil)
unless id
def fetch_resource(uri, id_is_known, on_behalf_of = nil)
unless id_is_known
json = fetch_resource_without_id_validation(uri, on_behalf_of)
return if !json.is_a?(Hash) || unsupported_uri_scheme?(json['id'])