Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 10 additions & 5 deletions app/controllers/saml_idp_controller.rb
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,16 @@ def remotelogout
handle_valid_sp_remote_logout_request(user_id)
end

def external_saml_request?
return true if request.path.start_with?('/api/saml/authpost')

begin
URI(request.referer).host != request.host
rescue ArgumentError, URI::Error
false
end
end

private

def confirm_user_is_authenticated_with_fresh_mfa
Expand Down Expand Up @@ -118,11 +128,6 @@ def log_external_saml_auth_request
)
end

def external_saml_request?
(!request.referer.nil? && URI(request.referer).host != request.host) ||
request.path.start_with?('/api/saml/authpost')
end

def handle_successful_handoff
track_events
delete_branded_experience
Expand Down
11 changes: 11 additions & 0 deletions spec/controllers/saml_idp_controller_spec.rb
Original file line number Diff line number Diff line change
Expand Up @@ -1802,4 +1802,15 @@ def stub_requested_attributes
)
end
end

describe '#external_saml_request' do
it 'returns false for malformed referer' do
request.env['HTTP_REFERER'] = '{{<script>console.log()</script>'
expect(subject.external_saml_request?).to eq false
end

it 'returns false for empty referer' do
expect(subject.external_saml_request?).to eq false
end
end
end