Don't leak allowed origins in error message
This commit is contained in:
parent
3c4bc6ae35
commit
9ac96cdd50
1 changed files with 1 additions and 1 deletions
|
@ -735,7 +735,7 @@ class UiRequest(object):
|
|||
origin_host = origin.split("://", 1)[-1]
|
||||
if origin_host != host and origin_host not in self.server.allowed_ws_origins:
|
||||
ws.send(json.dumps({"error": "Invalid origin: %s" % origin}))
|
||||
return self.error403("Invalid origin: %s %s" % (origin, self.server.allowed_ws_origins))
|
||||
return self.error403("Invalid origin: %s" % origin)
|
||||
|
||||
# Find site by wrapper_key
|
||||
wrapper_key = self.get["wrapper_key"]
|
||||
|
|
Loading…
Reference in a new issue