Skip to content

Harden LNURL-auth request handling#862

Open
benthecarman wants to merge 1 commit intolightningdevkit:mainfrom
benthecarman:ssrf-lnurl
Open

Harden LNURL-auth request handling#862
benthecarman wants to merge 1 commit intolightningdevkit:mainfrom
benthecarman:ssrf-lnurl

Conversation

@benthecarman
Copy link
Copy Markdown
Contributor

Enforce HTTPS for non-localhost URLs per LNURL spec and disable redirect following since the auth flow is a single GET request.

Enforce HTTPS for non-localhost URLs per LNURL spec and disable
redirect following since the auth flow is a single GET request.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@ldk-reviews-bot
Copy link
Copy Markdown

ldk-reviews-bot commented Apr 1, 2026

I've assigned @tnull as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@ldk-reviews-bot ldk-reviews-bot requested a review from tnull April 1, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants