Refuse an origin with a * inside at startup (closes #61)

access_control_allow_origin accepted values such as https://* or
https://*example.com, which the CORS middleware reads as a pattern that
lets other sites read responses. Any value that contains * and is not
exactly * now aborts startup naming the key, its variable and the value.

Model: opus-5-5
This commit is contained in:
2026-09-29 00:19:07 +00:00
parent 7a969bb225
commit 3fdb7faab1
+6 -2
View File
@@ -611,7 +611,10 @@ func (c *Config) validate() error {
// validateAccessControlAllowOrigin checks that access_control_allow_origin
// is "*" or one origin, a scheme and host with nothing after them, as
// browsers send it in the Origin header. Anything else, such as a bare
// hostname or a trailing slash, would match no request.
// hostname or a trailing slash, would match no request. An origin with a
// "*" inside, such as https://*example.com, is refused because the CORS
// middleware reads that "*" as a pattern and would let other sites read
// responses.
func (c *Config) validateAccessControlAllowOrigin() error {
origin := c.AccessControlAllowOrigin
if origin == "*" {
@@ -619,7 +622,8 @@ func (c *Config) validateAccessControlAllowOrigin() error {
}
parsed, err := url.Parse(origin)
if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin {
if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin ||
strings.Contains(origin, "*") {
return fmt.Errorf("%s: value %q is %w",
settingName(keyAccessControlAllowOrigin), origin, errNotAnOrigin)
}