Fix compliance page login redirect to custom domains

SafeRedirect previously matched against a single static host string,
so OIDC callbacks always fell back to the console instead of
redirecting back to compliance pages on custom domains. Refactor
AllowedHost into a dynamic AllowedHostFunc and wire a trust-service
lookup into the connect handler so custom domain hosts are accepted.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-03-31 10:51:34 +02:00
parent 573e4f17f8
commit 419c93fc7d
9 changed files with 229 additions and 56 deletions

View File

@@ -81,7 +81,7 @@ func NewMux(
) *chi.Mux {
r := chi.NewMux()
safeRedirect := &saferedirect.SafeRedirect{AllowedHost: baseURL.Host()}
safeRedirect := saferedirect.New(saferedirect.StaticHosts(baseURL.Host()))
graphqlHandler := NewGraphQLHandler(iamSvc, proboSvc, esignSvc, mailmanSvc, customDomainCname, logger)
@@ -141,9 +141,9 @@ func NewMux(
var oauthSafeRedirect *saferedirect.SafeRedirect
switch provider {
case "SLACK":
oauthSafeRedirect = &saferedirect.SafeRedirect{AllowedHost: "slack.com"}
oauthSafeRedirect = saferedirect.New(saferedirect.StaticHosts("slack.com"))
case "GOOGLE_WORKSPACE":
oauthSafeRedirect = &saferedirect.SafeRedirect{AllowedHost: "accounts.google.com"}
oauthSafeRedirect = saferedirect.New(saferedirect.StaticHosts("accounts.google.com"))
}
oauthSafeRedirect.Redirect(w, r, redirectURL, "/", http.StatusSeeOther)
})