Skip to content

fix(proxy): validate host against allowlist to prevent open redirect (fixes #65)#68

Merged
ralyodio merged 1 commit into
profullstack:masterfrom
FuturMix:fix/proxy-open-redirect
Jun 14, 2026
Merged

fix(proxy): validate host against allowlist to prevent open redirect (fixes #65)#68
ralyodio merged 1 commit into
profullstack:masterfrom
FuturMix:fix/proxy-open-redirect

Conversation

@FuturMix

Copy link
Copy Markdown
Contributor

Validates the Host header against PUBLIC_DOMAIN (default logicsrc.com) instead of using it directly in the redirect URL. Prevents open redirect via crafted Host headers.

Fixes #65

@ralyodio ralyodio merged commit df040f4 into profullstack:master Jun 14, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Open redirect via Host header in proxy middleware

2 participants