From 34d62426c369395aec8ef96a4e7dd70a795cc3ec Mon Sep 17 00:00:00 2001 From: Tom Najdek Date: Thu, 25 Nov 2021 00:55:17 +0100 Subject: [PATCH 1/2] Tweak URL matching regexp to be more precise Institutional login process goes through multiple pages, the URL regexp is tweaked to be more precise to ensure that no arbitrary URLs are matched while polling for the final URL with auth code. --- chrome/content/zotero/fileInterface.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/chrome/content/zotero/fileInterface.js b/chrome/content/zotero/fileInterface.js index 2317b71c86..9e0e228048 100644 --- a/chrome/content/zotero/fileInterface.js +++ b/chrome/content/zotero/fileInterface.js @@ -857,7 +857,7 @@ var Zotero_File_Interface = new function() { this.authenticateMendeleyOnlinePoll = function (win) { if (win && win[0] && win[0].location) { - const matchResult = win[0].location.toString().match(/(?:\?|&)code=(.*?)(?:&|$)/i); + const matchResult = win[0].location.toString().match(/mendeley_oauth_redirect.html(?:.*?)(?:\?|&)code=(.*?)(?:&|$)/i); if (matchResult) { const mendeleyCode = matchResult[1]; Zotero.getMainWindow().setTimeout(() => this.showImportWizard({ mendeleyCode }), 0); From 1f6b626717b6b6d5e84cf877fa9b271f7c14a57c Mon Sep 17 00:00:00 2001 From: Tom Najdek Date: Thu, 25 Nov 2021 00:56:40 +0100 Subject: [PATCH 2/2] Change browser in basicViewer to be type="content" This fixes an issue where JS on a page loaded in the viewer would error when referring to window.top or window.parent. --- chrome/content/zotero/standalone/basicViewer.xul | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/chrome/content/zotero/standalone/basicViewer.xul b/chrome/content/zotero/standalone/basicViewer.xul index 67c7f3f8a4..91b458aa83 100644 --- a/chrome/content/zotero/standalone/basicViewer.xul +++ b/chrome/content/zotero/standalone/basicViewer.xul @@ -155,7 +155,7 @@ - +