fix(ui): validate baseUrl protocol before building SSO redirect URL in gotoLogin

Only allow http/https base URLs when constructing the window.location.href
target, falling back to a safe relative path to prevent DOM-based XSS (item #7).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
tyh.carl 2026-05-19 17:08:37 +08:00
parent 0135070577
commit 6137c16c0e

View file

@ -263,7 +263,8 @@ const UserDashboard: React.FC<UserDashboardProps> = ({
console.log("proxyBaseUrl:", baseUrl);
const url = baseUrl ? `${baseUrl}/sso/key/generate` : `/sso/key/generate`;
const safeBase = baseUrl && /^https?:\/\//.test(baseUrl) ? baseUrl : "";
const url = safeBase ? `${safeBase}/sso/key/generate` : `/sso/key/generate`;
console.log("Full URL:", url);
window.location.href = url;