瀏覽代碼

Merge pull request #451 from goecho/main

Fix bug: Header attributes (Host, Authorization, Origin, Referer) not sanitized.
Timothy Jaeryang Baek 1 年之前
父節點
當前提交
5c5bde3b85
共有 1 個文件被更改,包括 4 次插入4 次删除
  1. 4 4
      backend/apps/ollama/main.py

+ 4 - 4
backend/apps/ollama/main.py

@@ -65,10 +65,10 @@ async def proxy(path: str, request: Request, user=Depends(get_current_user)):
     else:
         raise HTTPException(status_code=401, detail=ERROR_MESSAGES.ACCESS_PROHIBITED)
 
-    headers.pop("Host", None)
-    headers.pop("Authorization", None)
-    headers.pop("Origin", None)
-    headers.pop("Referer", None)
+    headers.pop("host", None)
+    headers.pop("authorization", None)
+    headers.pop("origin", None)
+    headers.pop("referer", None)
 
     r = None