Something went wrong. Try again.
🌿 Collaborative wiki on ATProto
Something went wrong. Try again.
1.1 kB · 31 lines
TypeScript
at main
1234567891011121314151617181920212223242526272829303132import { resolvePublicUrl } from "./urls.ts";
// Only a path that cannot name another origin: "//evil.com" and "/\evil.com"// both leave the site. Checked after parsing, which is what a browser acts on.export function safeRedirectPath(raw: string | null | undefined): string { if (!raw?.startsWith("/")) return "/"; try { const base = "https://placeholder.invalid"; const url = new URL(raw, base); if (url.origin !== base) return "/"; const path = url.pathname + url.search + url.hash; return path.startsWith("//") || path.startsWith("/\\") ? "/" : path; } catch { return "/"; }}
// Where a form that has no page of its own sends the visitor back to. Referer is// the client's to set, so it decides nothing beyond a path on this site.export function safeRefererPath(request: Request): string { const referer = request.headers.get("referer"); if (!referer) return "/"; const site = resolvePublicUrl(request); try { const url = new URL(referer, site); if (url.host !== new URL(site).host) return "/"; return safeRedirectPath(url.pathname + url.search + url.hash); } catch { return "/"; }}