mirror of
https://github.com/pocketbase/pocketbase.git
synced 2026-10-05 14:01:43 +02:00
more strict cors quick subdomain checks to prevent misuse
This commit is contained in:
1 parent
768087993e
commit
5cdbca2b04
4 files changed
+5594
-5544
No files matched your search
+1
-1
@@ -6,7 +6,7 @@
|
||||
|
||||
- Updated `modernc.org/sqlite` to 1.59.0 _(minor performance improvement by switching to Go's `memmove` on Linux targets)_.
|
||||
|
||||
- Other minor fixes (godoc typos, normalized negative jsvm pool size, etc.).
|
||||
- Other minor fixes (godoc typos, normalized negative jsvm pool size, extra CORS wildcard subdomain checks to prevent misuse, etc.).
|
||||
|
||||
|
||||
## v0.40.4
|
||||
|
||||
@@ -211,7 +211,7 @@ func CORS(config CORSConfig) *hook.Handler[*core.RequestEvent] {
|
||||
allowOrigin = o
|
||||
break
|
||||
}
|
||||
if matchSubdomain(origin, o) {
|
||||
if exactWildcardMatch(origin, o) {
|
||||
allowOrigin = origin
|
||||
break
|
||||
}
|
||||
@@ -283,8 +283,8 @@ func matchScheme(domain, pattern string) bool {
|
||||
return didx != -1 && pidx != -1 && domain[:didx] == pattern[:pidx]
|
||||
}
|
||||
|
||||
// matchSubdomain compares authority with wildcard
|
||||
func matchSubdomain(domain, pattern string) bool {
|
||||
// exactWildcardMatch compares domain with a * wildcard pattern
|
||||
func exactWildcardMatch(domain, pattern string) bool {
|
||||
if !matchScheme(domain, pattern) {
|
||||
return false
|
||||
}
|
||||
@@ -312,18 +312,21 @@ func matchSubdomain(domain, pattern string) bool {
|
||||
patComp[i], patComp[opp] = patComp[opp], patComp[i]
|
||||
}
|
||||
|
||||
if len(patComp) != len(domComp) {
|
||||
return false
|
||||
}
|
||||
|
||||
for i, v := range domComp {
|
||||
if len(patComp) <= i {
|
||||
return false
|
||||
}
|
||||
p := patComp[i]
|
||||
|
||||
if p == "*" {
|
||||
return true
|
||||
continue
|
||||
}
|
||||
|
||||
if p != v {
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
return false
|
||||
return true
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
package apis
|
||||
|
||||
import "testing"
|
||||
|
||||
func TestCorsExactWildcardMatch(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
scenarios := []struct {
|
||||
domain string
|
||||
pattern string
|
||||
expected bool
|
||||
}{
|
||||
{"", "", false},
|
||||
{"http://example.com", "", false},
|
||||
{"", "http://example.com", false},
|
||||
{"http://example.com", "https://example.com", false},
|
||||
{"abc://example.com", "abc://example.com", true},
|
||||
{"https://example.com", "https://example.com", true},
|
||||
{"https://a.example.com", "https://example.com", false},
|
||||
{"https://example.com", "https://a.example.com", false},
|
||||
{"https://example.com", "https://*.example.com", false},
|
||||
{"https://a.example.com", "https://*.example.com", true},
|
||||
{"https://a.example.com", "https://a.*.example.com", false},
|
||||
{"https://a.b.example.com", "https://a.*.example.com", true},
|
||||
{"https://a.b.example.com", "https://a2.*.example.com", false},
|
||||
{"https://a.b.example.com", "https://a.*", false},
|
||||
{"https://a.b.example", "https://a.*", false},
|
||||
{"https://a.b", "https://a.*", true},
|
||||
}
|
||||
|
||||
for _, s := range scenarios {
|
||||
t.Run(s.domain+":"+s.pattern, func(t *testing.T) {
|
||||
result := exactWildcardMatch(s.domain, s.pattern)
|
||||
if result != s.expected {
|
||||
t.Fatalf("Expected %v, got %v", s.expected, result)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
+5543
-5535
File diff suppressed because it is too large.
Load diff
Reference in new issue
Block a user