getsentry / getsentry/sentry

Validate allowed origins list

Open
#77,998 1 comment 0 reactions 0 assignees View on GitHub
Improvement
Dominant language
Python
Stars
44.8k
Forks
4.9k
Avg merge
22h 21m
Merged PRs (30d)
586

Description

Need to investigate/brainstorm if this is best done on the BE or FE.
- on BE: validate in the POST handler
- on FE: find a way to access the form component's content, either onChange or onSubmit

This is currently set in a project option POST request, as one string (newline-separated list). Should validate:
- each is a valid URL without empty paths/domains (//, ..) or illegal characters
- scheme: decided with @ryan953 we'll only allow http and https for now. Missing scheme will be auto-formatted to one of the 2 (on FE)
- wildcard character (*): also decided with Ryan we'll only allow this for the left-most subdomain.

Display an appropriate error and help text on the FE. Could make use of the form component's onSubmitFail.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.