Remove duplicated logic

This commit is contained in:
Joel Speed 2017-12-11 09:24:52 +00:00
parent 543575a7ad
commit 3940d7e1cd
No known key found for this signature in database
GPG Key ID: 83695B8B3A376982

View File

@ -439,20 +439,13 @@ func (p *OAuthProxy) IsValidRedirect(redirect string) bool {
switch { switch {
case strings.HasPrefix(redirect, "/") && !strings.HasPrefix(redirect, "//"): case strings.HasPrefix(redirect, "/") && !strings.HasPrefix(redirect, "//"):
return true return true
case strings.HasPrefix(redirect, "http://"): case strings.HasPrefix(redirect, "http://") || strings.HasPrefix(redirect, "https://"):
redirect = strings.TrimPrefix(redirect, "http://") url, err := url.Parse(redirect)
redirect = strings.Split(redirect, "/")[0] if err != nil {
for _, domain := range p.whitelistDomains { return false
if strings.HasSuffix(redirect, domain) {
return true
}
} }
return false
case strings.HasPrefix(redirect, "https://"):
redirect = strings.TrimPrefix(redirect, "https://")
redirect = strings.Split(redirect, "/")[0]
for _, domain := range p.whitelistDomains { for _, domain := range p.whitelistDomains {
if strings.HasSuffix(redirect, domain) { if (url.Host == domain) || (strings.HasPrefix(domain, ".") && strings.HasSuffix(url.Host, domain)) {
return true return true
} }
} }