Open
Description
The package supports to automatically perform an Origin
header check via OriginPatterns
. However, these origin patterns are only checked against the Origin
header Host
component (see
Line 244 in efb626b
I believe that this is incorrect and the entire Origin
header should be checked against a set of allowed once - that is, including the schema and port.
Metadata
Metadata
Assignees
Labels
No labels