FEATURE: Allow wildcard in allowed_user_api_auth_redirects setting (#6779)

This commit is contained in:
Davide Porrovecchio
2019-02-26 17:03:20 +01:00
committed by Régis Hanol
parent 8c706b0ff7
commit 75aaae5d5c
4 changed files with 22 additions and 2 deletions

View File

@ -53,7 +53,7 @@ class UserApiKeysController < ApplicationController
if params.key?(:auth_redirect) && SiteSetting.allowed_user_api_auth_redirects
.split('|')
.none? { |u| params[:auth_redirect] == u }
.none? { |u| WildcardUrlChecker.check_url(u, params[:auth_redirect]) }
raise Discourse::InvalidAccess
end