mirror of
https://github.com/discourse/discourse.git
synced 2025-05-29 01:31:35 +08:00
FEATURE: Allow wildcard in allowed_user_api_auth_redirects setting (#6779)
This commit is contained in:

committed by
Régis Hanol

parent
8c706b0ff7
commit
75aaae5d5c
@ -53,7 +53,7 @@ class UserApiKeysController < ApplicationController
|
||||
|
||||
if params.key?(:auth_redirect) && SiteSetting.allowed_user_api_auth_redirects
|
||||
.split('|')
|
||||
.none? { |u| params[:auth_redirect] == u }
|
||||
.none? { |u| WildcardUrlChecker.check_url(u, params[:auth_redirect]) }
|
||||
|
||||
raise Discourse::InvalidAccess
|
||||
end
|
||||
|
Reference in New Issue
Block a user