From 3bd6b3bd46bc48bf0054fbcf0b3798072610494f Mon Sep 17 00:00:00 2001 From: Yuri Kuznetsov Date: Mon, 6 Nov 2023 16:03:49 +0200 Subject: [PATCH] webhook allow http and https only --- application/Espo/Core/Webhook/Sender.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/application/Espo/Core/Webhook/Sender.php b/application/Espo/Core/Webhook/Sender.php index 03848317f1..83721acee7 100644 --- a/application/Espo/Core/Webhook/Sender.php +++ b/application/Espo/Core/Webhook/Sender.php @@ -92,6 +92,8 @@ class Sender curl_setopt($handler, \CURLOPT_CUSTOMREQUEST, 'POST'); curl_setopt($handler, \CURLOPT_CONNECTTIMEOUT, $connectTimeout); curl_setopt($handler, \CURLOPT_TIMEOUT, $timeout); + curl_setopt($handler, \CURLOPT_PROTOCOLS, \CURLPROTO_HTTPS | \CURLPROTO_HTTP); + curl_setopt($handler, \CURLOPT_REDIR_PROTOCOLS, \CURLPROTO_HTTPS); curl_setopt($handler, \CURLOPT_HTTPHEADER, $headerList); curl_setopt($handler, \CURLOPT_POSTFIELDS, $payload);