-
Notifications
You must be signed in to change notification settings - Fork 284
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(clerk-js,backend): Throw error if signInUrl is on same origin as a satellite app #1845
feat(clerk-js,backend): Throw error if signInUrl is on same origin as a satellite app #1845
Conversation
🦋 Changeset detectedLatest commit: cb9fc2d The changes in this PR will be included in the next version bump. This PR includes changesets to release 9 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
5b31c81
to
f74dd00
Compare
f74dd00
to
2e2864f
Compare
2e2864f
to
5822cae
Compare
if (signInUrl.origin === window.location.origin) { | ||
clerkInvalidSignInUrlOrigin(); | ||
} | ||
} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🙃
#validateMultiDomainOptions = () => {
// ...
if (this.#options.signInUrl) {
this.#assertSignInUrlFormatAndOrigin(this.#options.signInUrl, window.location.origin);
}
// ...
}
#assertSignInUrlFormatAndOrigin = (signInUrl: string, origin: string): never => {
try {
signInUrl = new URL(signInUrl);
} catch {
clerkInvalidSignInUrlFormat();
}
if (signInUrl.origin === window.location.origin) {
clerkInvalidSignInUrlOrigin();
}
}
5822cae
to
cb9fc2d
Compare
This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs. |
Description
Checklist
npm test
runs as expected.npm run build
runs as expected.Type of change
Packages affected
@clerk/clerk-js
@clerk/clerk-react
@clerk/nextjs
@clerk/remix
@clerk/types
@clerk/themes
@clerk/localizations
@clerk/clerk-expo
@clerk/backend
@clerk/clerk-sdk-node
@clerk/shared
@clerk/fastify
@clerk/chrome-extension
gatsby-plugin-clerk
build/tooling/chore