verify redirects are safe before redirecting

This commit is contained in:
Milo Schwartz 2025-01-09 23:21:57 -05:00
parent a556339b76
commit 6c813186b8
No known key found for this signature in database
18 changed files with 99 additions and 45 deletions

View file

@ -101,7 +101,8 @@ export async function verifyResourceSession(
return allowed(res);
}
const redirectUrl = `${config.getRawConfig().app.dashboard_url}/auth/resource/${encodeURIComponent(resource.resourceId)}?redirect=${encodeURIComponent(originalRequestURL)}`;
// const redirectUrl = `${config.getRawConfig().app.dashboard_url}/auth/resource/${encodeURIComponent(resource.resourceId)}?redirect=${encodeURIComponent(originalRequestURL)}`;
const redirectUrl = `${config.getRawConfig().app.dashboard_url}/auth/resource/${encodeURIComponent(resource.resourceId)}`;
if (!sessions) {
return notAllowed(res);