mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-05 02:41:56 +00:00
fix(ui): validate baseUrl protocol before building SSO redirect URL in gotoLogin
Only allow http/https base URLs when constructing the window.location.href target, falling back to a safe relative path to prevent DOM-based XSS (item #7). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
0135070577
commit
6137c16c0e
1 changed files with 2 additions and 1 deletions
|
|
@ -263,7 +263,8 @@ const UserDashboard: React.FC<UserDashboardProps> = ({
|
|||
|
||||
console.log("proxyBaseUrl:", baseUrl);
|
||||
|
||||
const url = baseUrl ? `${baseUrl}/sso/key/generate` : `/sso/key/generate`;
|
||||
const safeBase = baseUrl && /^https?:\/\//.test(baseUrl) ? baseUrl : "";
|
||||
const url = safeBase ? `${safeBase}/sso/key/generate` : `/sso/key/generate`;
|
||||
|
||||
console.log("Full URL:", url);
|
||||
window.location.href = url;
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue