diff --git a/copyparty/__main__.py b/copyparty/__main__.py index 1d7433382..39460bd47 100644 --- a/copyparty/__main__.py +++ b/copyparty/__main__.py @@ -1917,6 +1917,7 @@ def add_safety(ap): ap2.add_argument("--aclose", metavar="MIN", type=int, default=10, help="if a client maxes out the server connection limit, downgrade it from connection:keep-alive to connection:close for \033[33mMIN\033[0m minutes (and also kill its active connections) -- disable with 0") ap2.add_argument("--loris", metavar="B", type=int, default=60, help="if a client maxes out the server connection limit without sending headers, ban it for \033[33mB\033[0m minutes; disable with [\033[32m0\033[0m]") ap2.add_argument("--acao", metavar="V[,V]", type=u, default="*", help="Access-Control-Allow-Origin; list of origins (domains/IPs without port) to accept requests from; [\033[32mhttps://1.2.3.4\033[0m]. Default [\033[32m*\033[0m] allows requests from all sites but removes cookies and http-auth; only ?pw=hunter2 survives") + ap2.add_argument("--acao-re", metavar="PTN", type=u, default="", help="Access-Control-Allow-Origin; supplement to \033[33m--acao\033[0m; allow request if http-header 'Origin' matches either \033[33m--acao\033[0m or regex-\033[33mPTN\033[0m; ominous example: [\033[32m^moz-extension://.*\033[0m]") ap2.add_argument("--acam", metavar="V[,V]", type=u, default="GET,HEAD", help="Access-Control-Allow-Methods; list of methods to accept from offsite ('*' behaves like \033[33m--acao\033[0m's description)") if FULL_HELP or ANYWIN: ap2.add_argument("--unsafe-tools", action="store_true", help="windows-only: allow running programs (ffmpeg, dcraw_emu, ...) when their location is inside a folder that can be uploaded to (dangerous due to DLL-hijacking)") diff --git a/copyparty/httpcli.py b/copyparty/httpcli.py index 1c0fc4c96..5b55db480 100644 --- a/copyparty/httpcli.py +++ b/copyparty/httpcli.py @@ -1378,6 +1378,7 @@ class HttpCli(object): if ( self.args.pw_hdr in ih or re.sub(r"(:[0-9]{1,5})?/?$", "", origin) in good_origins + or (self.args.acao_re and self.args.acao_re.match(origin)) ): good_origin = True bad_hdrs = ("",) diff --git a/copyparty/svchub.py b/copyparty/svchub.py index 6b1dffe4f..b68d2fa48 100644 --- a/copyparty/svchub.py +++ b/copyparty/svchub.py @@ -1290,7 +1290,7 @@ class SvcHub(object): TH_BWRAP[:] = al.th_bwrap_b - zs = "dav_ua1 lf_url sus_urls nonsus_urls ua_nodav ua_nodoc ua_nozip" + zs = "acao_re dav_ua1 lf_url sus_urls nonsus_urls ua_nodav ua_nodoc ua_nozip" for k in zs.split(" "): vs = getattr(al, k) if not vs or vs == "no":