-
-
Notifications
You must be signed in to change notification settings - Fork 2.9k
Fix failing x-forwarded-host tests #14505
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🦋 Changeset detectedLatest commit: b97e24e The changes in this PR will be included in the next version bump. Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
CodSpeed Performance ReportMerging #14505 will not alter performanceComparing Summary
|
|
|
||
| // Validate X-Forwarded-Host against allowedDomains if configured | ||
| if (forwardedHost && !this.matchesAllowedDomains(forwardedHost, protocol)) { | ||
| if (forwardedHost && !this.matchesAllowedDomains(forwardedHost, protocol?.replace(':', ''))) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What's this replace?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
when the host header includes a port, ala example.com:8080
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It's when the protocol includes a : actually, I just noticed the code above, so https: -> https, got it
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Matthew Phillips <[email protected]> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Florian Lefebvre <[email protected]> Co-authored-by: Matthew Phillips <[email protected]> Co-authored-by: Houston (Bot) <[email protected]> Co-authored-by: Bartosz Kapciak <[email protected]> Co-authored-by: Bartosz Kapciak <[email protected]> Co-authored-by: Armand Philippot <[email protected]> Co-authored-by: Sarah Rainsberger <[email protected]> Co-authored-by: Abdelrahman Abdelfattah <[email protected]> Co-authored-by: Alasdair McLeay <[email protected]> Fix failing x-forwarded-host tests (#14505) fix(prefetch): Fix "tap" prefetch strategy when view transitions are enabled (#14235) fix `security.allowedDomains` version (#14509) Fix compatibility with older Astro versions in @astrojs/node (#14514) Fixes #14513 fix heading level in config reference docs (#14517) fix(deps): update all non-major dependencies (#14522)
Changes
Testing
Docs
N/A, bug fix