This commit is contained in:
Timur Ercan
2023-01-14 16:41:53 +01:00
parent 1a2ec58f3c
commit 39503b4ad7

View File

@ -1,26 +1,24 @@
// // import { CONSOLE_URL, WEBAPP_URL, WEBSITE_URL } from "@calcom/lib/constants"; // It ensures that redirection URL safe where it is accepted through a query params or other means where user can change it.
export const getSafeRedirectUrl = (url = "") => {
if (!url) {
return null;
}
// // It ensures that redirection URL safe where it is accepted through a query params or other means where user can change it. //It is important that this fn is given absolute URL because urls that don't start with HTTP can still deceive browser into redirecting to another domain
// export const getSafeRedirectUrl = (url = "") => { if (url.search(/^https?:\/\//) === -1) {
// if (!url) { throw new Error("Pass an absolute URL");
// return null; }
// }
// //It is important that this fn is given absolute URL because urls that don't start with HTTP can still deceive browser into redirecting to another domain const urlParsed = new URL(url);
// if (url.search(/^https?:\/\//) === -1) {
// throw new Error("Pass an absolute URL");
// }
// const urlParsed = new URL(url); // Avoid open redirection security vulnerability
if (
!["CONSOLE_URL", "WEBAPP_URL", "WEBSITE_URL"].some(
(u) => new URL(u).origin === urlParsed.origin
)
) {
url = `${"WEBAPP_URL"}/`;
}
// // Avoid open redirection security vulnerability return url;
// if ( };
// ![CONSOLE_URL, WEBAPP_URL, WEBSITE_URL].some(
// (u) => new URL(u).origin === urlParsed.origin
// )
// ) {
// url = `${WEBAPP_URL}/`;
// }
// return url;
// };