diff --git a/Controllers/CookieProxyController.cs b/Controllers/CookieProxyController.cs index 4ae86e3..5bf2b9f 100644 --- a/Controllers/CookieProxyController.cs +++ b/Controllers/CookieProxyController.cs @@ -12,7 +12,7 @@ public class CookieProxyController : Controller { [Route("/api/cookieproxy_stage_one")] public IActionResult StageOne([FromQuery] string tgt) { // Check if we are on the correct domain - if (Request.Host.Host != $"{Vars.AuthProxySubdomain}.{Vars.UpstreamPrimaryDomain}") + if (Request.Host.Host != $"{Vars.AuthProxySubdomain}.{Vars.UpstreamPrimaryDomain}" && Vars.PermittedDomains.All(p => Request.Host.Host != $"{Vars.AuthProxySubdomain}.{p}")) return StatusCode(StatusCodes.Status421MisdirectedRequest); var dstDomain = AuthHelpers.GetRootDomain(tgt);