Fix hardened security checks

This commit is contained in:
Laura Hausmann 2023-03-28 23:13:10 +02:00
parent b280eeba23
commit 627cd44d14
Signed by: zotan
GPG key ID: D044E84C5BE01605

View file

@ -12,7 +12,7 @@ public class CookieProxyController : Controller {
[Route("/api/cookieproxy_stage_one")]
public IActionResult StageOne([FromQuery] string dstDomain, [FromQuery] string tgt) {
// Check if we are on the correct domain
if (Request.Host.Host != Vars.AuthProxySubdomain + Vars.UpstreamPrimaryDomain)
if (Request.Host.Host != Vars.AuthProxySubdomain + "." + Vars.UpstreamPrimaryDomain)
return StatusCode(StatusCodes.Status421MisdirectedRequest);
if (!Request.Cookies.ContainsKey("authelia_session")