Skip to content

fix(authentication-oauth): Use actual URL origin comparison for origin check#3676

Merged
daffl merged 2 commits intodovefrom
oauth-url-redirect
Mar 21, 2026
Merged

fix(authentication-oauth): Use actual URL origin comparison for origin check#3676
daffl merged 2 commits intodovefrom
oauth-url-redirect

Conversation

@daffl
Copy link
Member

@daffl daffl commented Mar 19, 2026

This is a follow-up to #3653 and #3669 and uses the proper URL constructor to check the redirects instead of an arbitrary regex. Still passes all tests for existing vulnerabilities.

Copy link
Member

@marshallswain marshallswain left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One linty nit. :shipit:

@daffl daffl merged commit 32f04d0 into dove Mar 21, 2026
4 checks passed
@daffl daffl deleted the oauth-url-redirect branch March 21, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants