mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
Fix auth redirect url validation for app based urls with query params
This commit is contained in:
1 parent
81d960cdf0
commit
e39c69a7d4
2 files changed
+11
-1
No files matched your search
@@ -11,7 +11,8 @@ const baseDomainRegex =
|
||||
/^((ftp|http|https):\/\/)?(www.)?(?!.*(ftp|http|https|www.))[a-zA-Z0-9_*-]+(\.[a-zA-Z0-9_*-]+)+((\/)[\w#]+)*(\/\w+\?[a-zA-Z0-9_]+=\w+(&[a-zA-Z0-9_]+=\w+)*)+(?:\.[a-z]+)*(?::\d+)?(?![^<]*(?:<\/\w+>|\/?>))(.*)?\/?(.)*?$/gm
|
||||
|
||||
// iOS deep linking scheme https://benoitpasquier.com/deep-linking-url-scheme-ios/
|
||||
const appRegex = /^[a-z0-9]+([.][a-z0-9]+)*:\/(\/[-a-z0-9._~!$&'()*+,;=:@%]+)+$/i
|
||||
const appRegex =
|
||||
/^[a-z0-9]+([.][a-z0-9]+)*:\/(\/[-a-z0-9._~!$&'()*+,;=:@%]+)+(?:\.[a-z]+)*(?::\d+)?(?![^<]*(?:<\/\w+>|\/?>))(.*)?\/?(.)*?$/i
|
||||
|
||||
// Regex from https://stackoverflow.com/a/18696953/4807782
|
||||
const localhostRegex = /^(?:^|\s)((https?:\/\/)?(?:localhost|[\w-]+(?:\.[\w-]+)+)(:\d+)?(\/\S*)?)/i
|
||||
|
||||
@@ -18,6 +18,15 @@ describe('Auth.constants: domainRegex', () => {
|
||||
const output4 = domainRegex.test(mockInput4)
|
||||
expect(output4).toBe(true)
|
||||
})
|
||||
test('should validate app-based domains', () => {
|
||||
const mockInput1 = 'exp://exp.host/some-app'
|
||||
const output1 = domainRegex.test(mockInput1)
|
||||
expect(output1).toBe(true)
|
||||
|
||||
const mockInput2 = 'exp://exp.host/some-app?release-channel=default'
|
||||
const output2 = domainRegex.test(mockInput2)
|
||||
expect(output2).toBe(true)
|
||||
})
|
||||
test('should validate subdomains', () => {
|
||||
const mockInput1 = 'https://app.supabase.com'
|
||||
const output1 = domainRegex.test(mockInput1)
|
||||
|
||||
Reference in new issue
Block a user