mirror of
https://github.com/jayofelony/pwnagotchi.git
synced 2025-07-01 18:37:27 -04:00
Fix Origin header check bypass
This commit is contained in:
@ -141,7 +141,7 @@ class Handler(BaseHTTPRequestHandler):
|
|||||||
return False
|
return False
|
||||||
|
|
||||||
if Handler.AllowedOrigin != '*':
|
if Handler.AllowedOrigin != '*':
|
||||||
if origin != Handler.AllowedOrigin and not origin.starts_with(Handler.AllowedOrigin):
|
if origin != Handler.AllowedOrigin:
|
||||||
logging.warning("request with blocked Origin from %s: %s" % (self.address_string(), origin))
|
logging.warning("request with blocked Origin from %s: %s" % (self.address_string(), origin))
|
||||||
return False
|
return False
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user