-
Notifications
You must be signed in to change notification settings - Fork 1.4k
fix: compare URLs without protocols with checkOrigin: lax-proto #7865
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🦋 Changeset detectedLatest commit: cc7a14c The changes in this PR will be included in the next version bump. This PR includes changesets to release 4 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for your help @asaharan
Is there a specific issue with the actual code?
why are we changing it?
Yes @gioboa , even when I set checkOrigin to lax-proto, I get CSRF error.
|
built with Refined Cloudflare Pages Action⚡ Cloudflare Pages Deployment
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM 🌉
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please test the package generated by this PR and let us know if it's working as expected on your scenario. Thanks.
commit: |
Previously, two CSRF middlewares were added for lax-proto requests: one at the beginning and one at the end. This change replaces them with a single middleware placed at the beginning. Non-lax-proto cases remain unchanged.
protocol when checkOrigin is lax-proto
54047d0
to
a24ef39
Compare
@gioboa as csrf is being checked at the very beginning, origin contains http and not https. So, I have compare origin with inputOrigin after removing the protocol(http/https). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice, Thanks 👍
Co-authored-by: Giorgio Boa <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for your help @asaharan
Previously, two CSRF middlewares were added for lax-proto requests: one at the beginning and one at the end. This change replaces them with a single middleware placed at the beginning. Non-lax-proto cases remain unchanged.
What is it?
Description
fix behaviour of checkOrigin: "lax-proto" in createQwikCity
Checklist
pnpm change