Validate allowed origins list
- Dominant language
- Python
- Stars
- 44.8k
- Forks
- 4.9k
- Avg merge
- 22h 21m
- Merged PRs (30d)
- 586
Description
Need to investigate/brainstorm if this is best done on the BE or FE.
- on BE: validate in the POST handler
- on FE: find a way to access the form component's content, either onChange or onSubmit
This is currently set in a project option POST request, as one string (newline-separated list). Should validate:
- each is a valid URL without empty paths/domains (//, ..) or illegal characters
- scheme: decided with @ryan953 we'll only allow http and https for now. Missing scheme will be auto-formatted to one of the 2 (on FE)
- wildcard character (*): also decided with Ryan we'll only allow this for the left-most subdomain.
Display an appropriate error and help text on the FE. Could make use of the form component's onSubmitFail.
Contributor guide
Assessment
This issue has not been assessed yet.