Refuse an origin with a * inside at startup (closes #61)
check / check (push) Successful in 3m11s

access_control_allow_origin accepted values such as https://* or
https://*example.com, which the CORS middleware reads as a pattern that
lets other sites read responses. Any value that contains * and is not
exactly * now aborts startup naming the key, its variable and the value.

Model: opus-5-5
This commit is contained in:
2026-09-28 18:39:33 +00:00
parent 4afe8c3ad1
commit d2e2d7759d
+6 -2
View File
@@ -611,7 +611,10 @@ func (c *Config) validate() error {
// validateAccessControlAllowOrigin checks that access_control_allow_origin // validateAccessControlAllowOrigin checks that access_control_allow_origin
// is "*" or one origin, a scheme and host with nothing after them, as // is "*" or one origin, a scheme and host with nothing after them, as
// browsers send it in the Origin header. Anything else, such as a bare // browsers send it in the Origin header. Anything else, such as a bare
// hostname or a trailing slash, would match no request. // hostname or a trailing slash, would match no request. An origin with a
// "*" inside, such as https://*example.com, is refused because the CORS
// middleware reads that "*" as a pattern and would let other sites read
// responses.
func (c *Config) validateAccessControlAllowOrigin() error { func (c *Config) validateAccessControlAllowOrigin() error {
origin := c.AccessControlAllowOrigin origin := c.AccessControlAllowOrigin
if origin == "*" { if origin == "*" {
@@ -619,7 +622,8 @@ func (c *Config) validateAccessControlAllowOrigin() error {
} }
parsed, err := url.Parse(origin) parsed, err := url.Parse(origin)
if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin { if err != nil || parsed.Host == "" || parsed.Scheme+"://"+parsed.Host != origin ||
strings.Contains(origin, "*") {
return fmt.Errorf("%s: value %q is %w", return fmt.Errorf("%s: value %q is %w",
settingName(keyAccessControlAllowOrigin), origin, errNotAnOrigin) settingName(keyAccessControlAllowOrigin), origin, errNotAnOrigin)
} }