From 3fdb7faab1288bfd141e0e63db7cc5b050d52838 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Mon, 28 Sep 2026 19:51:14 +0000 Subject: [PATCH] Refuse an origin with a * inside at startup (closes #61) access_control_allow_origin accepted values such as https://* or https://*example.com, which the CORS middleware reads as a pattern that lets other sites read responses. Any value that contains * and is not exactly * now aborts startup naming the key, its variable and the value. Model: opus-5-5 --- internal/config/config.go | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/internal/config/config.go b/internal/config/config.go index 20bdf83..4f63900 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -611,7 +611,10 @@ func (c *Config) validate() error { // validateAccessControlAllowOrigin checks that access_control_allow_origin // is "*" or one origin, a scheme and host with nothing after them, as // browsers send it in the Origin header. Anything else, such as a bare -// hostname or a trailing slash, would match no request. +// hostname or a trailing slash, would match no request. An origin with a +// "*" inside, such as https://*example.com, is refused because the CORS +// middleware reads that "*" as a pattern and would let other sites read +// responses. func (c *Config) validateAccessControlAllowOrigin() error { origin := c.AccessControlAllowOrigin if origin == "*" { @@ -619,7 +622,8 @@ func (c *Config) validateAccessControlAllowOrigin() error { } parsed, err := url.Parse(origin) - if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin { + if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin || + strings.Contains(origin, "*") { return fmt.Errorf("%s: value %q is %w", settingName(keyAccessControlAllowOrigin), origin, errNotAnOrigin) }