Don't log invalid redirect if redirect is empty

This commit is contained in:
Joel Speed
2020-06-19 18:17:05 +01:00
parent 713c3927a9
commit dc756b9de3
2 changed files with 4 additions and 0 deletions
+3
View File
@@ -598,6 +598,9 @@ func validOptionalPort(port string) bool {
// IsValidRedirect checks whether the redirect URL is whitelisted
func (p *OAuthProxy) IsValidRedirect(redirect string) bool {
switch {
case redirect == "":
// The user didn't specify a redirect, should fallback to `/`
return false
case strings.HasPrefix(redirect, "/") && !strings.HasPrefix(redirect, "//") && !invalidRedirectRegex.MatchString(redirect):
return true
case strings.HasPrefix(redirect, "http://") || strings.HasPrefix(redirect, "https://"):