Merge pull request #949 from Hexastack/948-fix-skip-invalid-url-wildcard-cors

Filter out wildcard origins from allowed domains
This commit is contained in:
Yassine
2025-04-25 09:52:55 +01:00
committed by GitHub

View File

@@ -337,6 +337,7 @@ export default abstract class BaseWebChannelHandler<
// Get the allowed origins
const origins: string[] = settings.allowed_domains.split(',');
const foundOrigin = origins
.filter((origin) => origin.trim() !== '*') // Skip "*"
.map((origin) => {
try {
return new URL(origin.trim()).origin;