fix: use X-Forwarded-Uri if it exists for pathRegex match
This commit is contained in:
parent
474f08f538
commit
ad8ba07b21
|
|
@ -22,6 +22,7 @@
|
|||
- [#2013](https://github.com/oauth2-proxy/oauth2-proxy/pull/2013) Upgrade alpine to version 3.17.2 and library dependencies (@miguelborges99)
|
||||
- [#2028](https://github.com/oauth2-proxy/oauth2-proxy/pull/2028) Update golang.org/x/net to v0.7.0 ato address GHSA-vvpx-j8f3-3w6h
|
||||
- [#2047](https://github.com/oauth2-proxy/oauth2-proxy/pull/2047) CVE-2022-41717: DoS in Go net/http may lead to DoS (@miguelborges99
|
||||
- [#2133](https://github.com/oauth2-proxy/oauth2-proxy/pull/2133) Use X-Forwarded-Uri if it exists for pathRegex match
|
||||
|
||||
# V7.4.0
|
||||
|
||||
|
|
|
|||
|
|
@ -578,7 +578,7 @@ func isAllowedMethod(req *http.Request, route allowedRoute) bool {
|
|||
}
|
||||
|
||||
func isAllowedPath(req *http.Request, route allowedRoute) bool {
|
||||
matches := route.pathRegex.MatchString(req.URL.Path)
|
||||
matches := route.pathRegex.MatchString(requestutil.GetRequestURI(req))
|
||||
|
||||
if route.negate {
|
||||
return !matches
|
||||
|
|
@ -599,7 +599,7 @@ func (p *OAuthProxy) isAllowedRoute(req *http.Request) bool {
|
|||
|
||||
func (p *OAuthProxy) isAPIPath(req *http.Request) bool {
|
||||
for _, route := range p.apiRoutes {
|
||||
if route.pathRegex.MatchString(req.URL.Path) {
|
||||
if route.pathRegex.MatchString(requestutil.GetRequestURI(req)) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue