feat : update
This commit is contained in:
@@ -7,7 +7,7 @@ describe("public auth return path", () => {
|
||||
});
|
||||
|
||||
it("rejects external destinations and auth loops", () => {
|
||||
for (const value of ["https://example.com", "//example.com", "/\\example.com", "/login", "/lo%67in", "/register", "/admin/login", 4])
|
||||
for (const value of ["https://example.com", "//example.com", "/\\example.com", "/login", "/lo%67in", "/register", "/auth/login", "/auth/register", "/auth/check-email", "/auth/password-reset", "/admin/login", 4])
|
||||
expect(safeAuthReturnPath(value)).toBe("/");
|
||||
});
|
||||
});
|
||||
|
||||
@@ -3,7 +3,7 @@ export function safeAuthReturnPath(value: unknown): string {
|
||||
try {
|
||||
const url = new URL(value, "https://auth.local");
|
||||
const path = decodeURIComponent(url.pathname);
|
||||
if (url.origin !== "https://auth.local" || ["/login", "/register", "/commission/login", "/admin/login"].includes(path))
|
||||
if (url.origin !== "https://auth.local" || path === "/auth" || path.startsWith("/auth/") || ["/login", "/register", "/commission/login", "/admin/login"].includes(path))
|
||||
return "/";
|
||||
return `${url.pathname}${url.search}${url.hash}`;
|
||||
} catch {
|
||||
|
||||
@@ -187,7 +187,6 @@ export async function listAdminTeamImportGuides(excludeGuideId: string) {
|
||||
id: guides.id,
|
||||
name: guides.name,
|
||||
characterKey: guides.characterKey,
|
||||
isPublic: guides.isPublic,
|
||||
coverObjectKey: media.objectKey,
|
||||
})
|
||||
.from(guides)
|
||||
|
||||
Reference in New Issue
Block a user