Refuse an origin with a * inside at startup (closes #61)
access_control_allow_origin accepted values such as https://* or https://*example.com, which the CORS middleware reads as a pattern that lets other sites read responses. Any value that contains * and is not exactly * now aborts startup naming the key, its variable and the value. Model: opus-5-5
This commit is contained in:
@@ -611,7 +611,10 @@ func (c *Config) validate() error {
|
|||||||
// validateAccessControlAllowOrigin checks that access_control_allow_origin
|
// validateAccessControlAllowOrigin checks that access_control_allow_origin
|
||||||
// is "*" or one origin, a scheme and host with nothing after them, as
|
// is "*" or one origin, a scheme and host with nothing after them, as
|
||||||
// browsers send it in the Origin header. Anything else, such as a bare
|
// browsers send it in the Origin header. Anything else, such as a bare
|
||||||
// hostname or a trailing slash, would match no request.
|
// hostname or a trailing slash, would match no request. An origin with a
|
||||||
|
// "*" inside, such as https://*example.com, is refused because the CORS
|
||||||
|
// middleware reads that "*" as a pattern and would let other sites read
|
||||||
|
// responses.
|
||||||
func (c *Config) validateAccessControlAllowOrigin() error {
|
func (c *Config) validateAccessControlAllowOrigin() error {
|
||||||
origin := c.AccessControlAllowOrigin
|
origin := c.AccessControlAllowOrigin
|
||||||
if origin == "*" {
|
if origin == "*" {
|
||||||
@@ -619,7 +622,8 @@ func (c *Config) validateAccessControlAllowOrigin() error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
parsed, err := url.Parse(origin)
|
parsed, err := url.Parse(origin)
|
||||||
if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin {
|
if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin ||
|
||||||
|
strings.Contains(origin, "*") {
|
||||||
return fmt.Errorf("%s: value %q is %w",
|
return fmt.Errorf("%s: value %q is %w",
|
||||||
settingName(keyAccessControlAllowOrigin), origin, errNotAnOrigin)
|
settingName(keyAccessControlAllowOrigin), origin, errNotAnOrigin)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user