와일드카드 URL 체크기에 하드코딩된 프로토콜 허용 목록이 있습니다

Since the following commit:

https://github.com/discourse/discourse/commit/d8360b4c82ca34a5c570a4af28b628f68fb23908#diff-cafbd2eee0eb3198218bc6b0ef1c0fa0R4

a hardcoded list of allowed protocols has been added, ignoring what we have configured in the administration UI:

… leading to any attempt to create a new user API key with fivem://accept-auth as redirect URI hitting a 403 without any information in /logs or on the end user’s screen.

5개의 좋아요

Hi there,

Thanks for reporting this to us, we’ll get someone to look at it as soon as possible.

2개의 좋아요

Thanks for reporting this, we are looking at a fix so we auto whitelist fivem if we notice it in the allowed_user_api_auth_redirects list.

4개의 좋아요

I opened a PR here:

https://github.com/discourse/discourse/pull/8651

We check the entire URL (including protocol) against the site setting list, so I don’t think there is any need for a specific whitelist.

8개의 좋아요

This is now merged. @blattersturm if you update to the latest version, the problem should be resolved.

7개의 좋아요

This topic was automatically closed after 4 days. New replies are no longer allowed.