fix(auth): accept configured public origin for sign-in
This commit is contained in:
+3
-3
@@ -53,6 +53,7 @@ from .logging_config import (
|
||||
from .runtime import get_runtime_settings
|
||||
from .metrics import record_api, start_metrics
|
||||
from .secret_storage import validate_secret_storage_configuration
|
||||
from .services.request_origins import is_allowed_request_origin
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
_background_tasks: list[asyncio.Task[None]] = []
|
||||
@@ -87,9 +88,8 @@ async def log_requests_and_add_security_headers(request: Request, call_next):
|
||||
)
|
||||
request.state.request_id = request_id
|
||||
if request.method.upper() not in {"GET", "HEAD", "OPTIONS"}:
|
||||
origin = str(request.headers.get("origin") or "").rstrip("/")
|
||||
allowed_origin = str(settings.cors_allow_origin or "").rstrip("/")
|
||||
if origin and origin != allowed_origin:
|
||||
origin = str(request.headers.get("origin") or "")
|
||||
if origin and not is_allowed_request_origin(origin):
|
||||
record_api(request, 403, 0.0)
|
||||
if operation_id and operation_token is not None:
|
||||
finish_operation(operation_id, success=False, status_code=403)
|
||||
|
||||
Reference in New Issue
Block a user