Skip to content
This repository was archived by the owner on Mar 3, 2022. It is now read-only.

Commit 202a057

Browse files
authoredJan 28, 2021
Merge pull request #1223 from paulmowat/fix/postMessageUrlCheck
IFrameWindow.js _message url checks
2 parents f0c08c5 + c8f45fb commit 202a057

11 files changed

+18
-17
lines changed
 

‎dist/oidc-client.js

+2-2
Large diffs are not rendered by default.

‎dist/oidc-client.min.js

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/oidc-client.rsa256.slim.js

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/oidc-client.rsa256.slim.min.js

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/oidc-client.slim.js

+2-2
Large diffs are not rendered by default.

‎dist/oidc-client.slim.min.js

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎lib/oidc-client.js

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎lib/oidc-client.min.js

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎lib/oidc-client.rsa256.js

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎lib/oidc-client.rsa256.min.js

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎src/IFrameWindow.js

+2-1
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,8 @@ export class IFrameWindow {
8686

8787
if (this._timer &&
8888
e.origin === this._origin &&
89-
e.source === this._frame.contentWindow
89+
e.source === this._frame.contentWindow &&
90+
(typeof e.data === 'string' && (e.data.startsWith('http://') || e.data.startsWith('https://')))
9091
) {
9192
let url = e.data;
9293
if (url) {

0 commit comments

Comments
 (0)
This repository has been archived.