From dbfbb2b5824fb7e13083e6f2962432f9ecf8d898 Mon Sep 17 00:00:00 2001 From: medchedli Date: Tue, 22 Apr 2025 16:12:30 +0100 Subject: [PATCH] fix: filter out wildcard origins from allowed domains --- api/src/extensions/channels/web/base-web-channel.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/api/src/extensions/channels/web/base-web-channel.ts b/api/src/extensions/channels/web/base-web-channel.ts index 6d4014b8..c5814144 100644 --- a/api/src/extensions/channels/web/base-web-channel.ts +++ b/api/src/extensions/channels/web/base-web-channel.ts @@ -337,6 +337,7 @@ export default abstract class BaseWebChannelHandler< // Get the allowed origins const origins: string[] = settings.allowed_domains.split(','); const foundOrigin = origins + .filter((origin) => origin.trim() !== '*') // Skip "*" .map((origin) => { try { return new URL(origin.trim()).origin;