mirror of
https://gitflic.ru/project/openide/openide.git
synced 2026-09-27 10:03:11 +07:00
check Host
This commit is contained in:
@@ -43,8 +43,12 @@ public abstract class HttpRequestHandler {
|
||||
return false;
|
||||
}
|
||||
|
||||
@SuppressWarnings("SpellCheckingInspection")
|
||||
public boolean isAccessible(@NotNull HttpRequest request) {
|
||||
return NettyKt.isLocalOrigin(request);
|
||||
String host = NettyKt.getHost(request);
|
||||
// If attacker.com DNS rebound to 127.0.0.1 and user open site directly — no Origin or Referer headers.
|
||||
// So we should check Host header.
|
||||
return host != null && NettyKt.isLocalOrigin(request) && NettyKt.parseAndCheckIsLocalHost(host);
|
||||
}
|
||||
|
||||
public boolean isSupported(@NotNull FullHttpRequest request) {
|
||||
|
||||
@@ -153,7 +153,8 @@ private fun isTrustedChromeExtension(uri: URI): Boolean {
|
||||
return uri.scheme == "chrome-extension" && (uri.host == "hmhgeddbohgjknpmjagkdomcpobmllji" || uri.host == "offnedcbhjldheanlbojaefbfbllddna")
|
||||
}
|
||||
|
||||
private fun parseAndCheckIsLocalHost(uri: String?, onlyAnyOrLoopback: Boolean): Boolean {
|
||||
@JvmOverloads
|
||||
fun parseAndCheckIsLocalHost(uri: String?, onlyAnyOrLoopback: Boolean = true): Boolean {
|
||||
if (uri == null) {
|
||||
return true
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user