Use hostname checking csrf referer whitelist instead of host.
In current version, www.alipay.net:8000 will not match refererWhiteList: [ 'alipay.net' ].
Maybe it is necessary to change host to hostname when checking a url whether in refererWhiteList.
Checklist
npm test
passesAffected core subsystem(s)
egg-security
Description of change
Use hostname checking csrf referer whitelist instead of host. In current version,
www.alipay.net:8000
will not matchrefererWhiteList: [ 'alipay.net' ]
. Maybe it is necessary to changehost
tohostname
when checking a url whether inrefererWhiteList
.