diff --git a/core/src/main/groovy/com/muwire/core/connection/ConnectionAcceptor.groovy b/core/src/main/groovy/com/muwire/core/connection/ConnectionAcceptor.groovy index 75664f4e..eb735576 100644 --- a/core/src/main/groovy/com/muwire/core/connection/ConnectionAcceptor.groovy +++ b/core/src/main/groovy/com/muwire/core/connection/ConnectionAcceptor.groovy @@ -333,8 +333,11 @@ class ConnectionAcceptor { Persona browser = null Map headers = DataUtil.readAllHeaders(dis); - if (headers.containsKey('Persona')) + if (headers.containsKey('Persona')) { browser = new Persona(new ByteArrayInputStream(Base64.decode(headers['Persona']))) + if (browser.destination != e.destination) + throw new IOException("browser persona mismatch") + } OutputStream os = e.getOutputStream() if (!settings.browseFiles) {