eggjs / egg-security

Security plugin for egg, force performance too.
MIT License
238 stars 43 forks source link

feat: use hostname checking csrf referer whitelist instead of host #71

Closed hq5544 closed 9 months ago

hq5544 commented 3 years ago
Checklist
Affected core subsystem(s)

egg-security

Description of change

Use hostname checking csrf referer whitelist instead of host. In current version, www.alipay.net:8000 will not match refererWhiteList: [ 'alipay.net' ]. Maybe it is necessary to change host to hostname when checking a url whether in refererWhiteList.