fix(auth): bound OIDC initiation and transport
This commit is contained in:
@@ -10,6 +10,7 @@ import type {
|
||||
Permission,
|
||||
Role,
|
||||
} from "./types.js";
|
||||
import { parseConfiguredTransportUrl } from "./url-policy.js";
|
||||
|
||||
export type {
|
||||
AuthenticationConfig,
|
||||
@@ -81,25 +82,12 @@ function readBoundedConfig(path: string): { source: string; identity: FileIdenti
|
||||
}
|
||||
}
|
||||
|
||||
function loopbackHost(host: string): boolean {
|
||||
return host === "::1" || /^127(?:\.\d{1,3}){3}$/.test(host);
|
||||
}
|
||||
|
||||
function validOrigin(value: string, httpLoopbackAllowed: boolean): boolean {
|
||||
try {
|
||||
const url = new URL(value);
|
||||
return (url.protocol === "https:" || (httpLoopbackAllowed && url.protocol === "http:" && loopbackHost(url.hostname)))
|
||||
&& url.username.length === 0 && url.password.length === 0 && url.pathname === "/"
|
||||
&& url.search.length === 0 && url.hash.length === 0;
|
||||
} catch { return false; }
|
||||
return parseConfiguredTransportUrl(value, { allowLoopbackHttp: httpLoopbackAllowed, originOnly: true }) !== undefined;
|
||||
}
|
||||
|
||||
function validIssuer(value: string): boolean {
|
||||
try {
|
||||
const url = new URL(value);
|
||||
return url.protocol === "https:" && url.username.length === 0 && url.password.length === 0
|
||||
&& url.search.length === 0 && url.hash.length === 0;
|
||||
} catch { return false; }
|
||||
return parseConfiguredTransportUrl(value, { allowLoopbackHttp: false }) !== undefined;
|
||||
}
|
||||
|
||||
function validUsersFile(value: string): boolean {
|
||||
|
||||
Reference in New Issue
Block a user