more strict cors quick subdomain checks to prevent misuse

This commit is contained in:
Gani Georgiev committed 2026-09-26 10:25:19 +03:00
1 parent 768087993e
commit 5cdbca2b04
4 files changed
+5594 -5544

No files matched your search

+1 -1
View File
@@ -6,7 +6,7 @@
- Updated `modernc.org/sqlite` to 1.59.0 _(minor performance improvement by switching to Go's `memmove` on Linux targets)_.
- Other minor fixes (godoc typos, normalized negative jsvm pool size, etc.).
- Other minor fixes (godoc typos, normalized negative jsvm pool size, extra CORS wildcard subdomain checks to prevent misuse, etc.).
## v0.40.4
+11 -8
View File
@@ -211,7 +211,7 @@ func CORS(config CORSConfig) *hook.Handler[*core.RequestEvent] {
allowOrigin = o
break
}
if matchSubdomain(origin, o) {
if exactWildcardMatch(origin, o) {
allowOrigin = origin
break
}
@@ -283,8 +283,8 @@ func matchScheme(domain, pattern string) bool {
return didx != -1 && pidx != -1 && domain[:didx] == pattern[:pidx]
}
// matchSubdomain compares authority with wildcard
func matchSubdomain(domain, pattern string) bool {
// exactWildcardMatch compares domain with a * wildcard pattern
func exactWildcardMatch(domain, pattern string) bool {
if !matchScheme(domain, pattern) {
return false
}
@@ -312,18 +312,21 @@ func matchSubdomain(domain, pattern string) bool {
patComp[i], patComp[opp] = patComp[opp], patComp[i]
}
if len(patComp) != len(domComp) {
return false
}
for i, v := range domComp {
if len(patComp) <= i {
return false
}
p := patComp[i]
if p == "*" {
return true
continue
}
if p != v {
return false
}
}
return false
return true
}
+39
View File
@@ -0,0 +1,39 @@
package apis
import "testing"
func TestCorsExactWildcardMatch(t *testing.T) {
t.Parallel()
scenarios := []struct {
domain string
pattern string
expected bool
}{
{"", "", false},
{"http://example.com", "", false},
{"", "http://example.com", false},
{"http://example.com", "https://example.com", false},
{"abc://example.com", "abc://example.com", true},
{"https://example.com", "https://example.com", true},
{"https://a.example.com", "https://example.com", false},
{"https://example.com", "https://a.example.com", false},
{"https://example.com", "https://*.example.com", false},
{"https://a.example.com", "https://*.example.com", true},
{"https://a.example.com", "https://a.*.example.com", false},
{"https://a.b.example.com", "https://a.*.example.com", true},
{"https://a.b.example.com", "https://a2.*.example.com", false},
{"https://a.b.example.com", "https://a.*", false},
{"https://a.b.example", "https://a.*", false},
{"https://a.b", "https://a.*", true},
}
for _, s := range scenarios {
t.Run(s.domain+":"+s.pattern, func(t *testing.T) {
result := exactWildcardMatch(s.domain, s.pattern)
if result != s.expected {
t.Fatalf("Expected %v, got %v", s.expected, result)
}
})
}
}
File diff suppressed because it is too large. Load diff