appirio-tech / accounts-app

accounts.topcoder.com
2 stars 25 forks source link

Fix security issue with allowed origins #214

Closed ThomasKranitsas closed 5 years ago

ThomasKranitsas commented 5 years ago

This will check the naked domain.

So, you'll just have to allow a domain like topcoder.com and any *.topcoder.com/**/** will be valid.