Jump to content


Whitelisting URL for a Link Widget


1 reply to this topic

#1 drethan

    Member

  • Members
  • PipPip
  • 19 posts

Posted 02 October 2019 - 01:11 PM

Is there any option to only allow a certain website or websites to use a specific chat widget? Technically someone can scrape the script tag from the bottom of the website and place it on their own site...

#2 drethan

    Member

  • Members
  • PipPip
  • 19 posts

Posted 04 October 2019 - 08:08 PM

Well if anyone else is curious or wants to implement something similar this is what we ended up doing... ( Note: This wont be widget specific but instead will only allow certain domains to poll your livezilla server )...

I am using apache on my webserver so if your using nginx you may have to see if there is an equivalent.

I created a .htaccess file in my livezilla root folder

# Restrict Access to LiveZilla unless from a valid referrer
<FilesMatch "server\.php|script\.php">
RewriteEngine On

# Is the request from a valid domain?
RewriteCond %{HTTP_REFERER} .*example.com.*$ [OR]
RewriteCond %{HTTP_REFERER} .*exampleTwo.com.*$ [OR]
RewriteCond %{HTTP_REFERER} .*example.org.*$

# If so, skip the next Rewrite Rule which redirects to a 403
RewriteRule ".?" "-" [S=1]

RewriteRule .* - [F]
</FilesMatch>





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users