diff --git a/pkg/probod/probod.go b/pkg/probod/probod.go index f51e5f609..9bc066a36 100644 --- a/pkg/probod/probod.go +++ b/pkg/probod/probod.go @@ -767,7 +767,13 @@ func newTrustCenterHTTPRedirectHandler(proboService *probo.Service, l *log.Logge } // This is a trust center domain, redirect to HTTPS - httpsURL := "https://" + r.Host + r.URL.RequestURI() + base, err := baseurl.Parse("https://" + domain) + if err != nil { + httpserver.RenderError(w, http.StatusNotFound, errors.New("not found")) + return + } + + httpsURL := base.WithPath(r.URL.Path).WithQueryValues(r.URL.Query()).MustString() l.InfoCtx( ctx, "HTTP request to trust center custom domain, redirecting to HTTPS", diff --git a/pkg/server/server.go b/pkg/server/server.go index 2c6e55a51..ed14cab44 100644 --- a/pkg/server/server.go +++ b/pkg/server/server.go @@ -17,6 +17,7 @@ package server import ( "errors" "net/http" + "path" "strings" "github.com/go-chi/chi/v5" @@ -156,7 +157,8 @@ func (s *Server) stripTrustPrefix(next http.Handler) http.Handler { prefix := "/trust/" + slugOrId if r.URL.Path == prefix { - http.Redirect(w, r, prefix+"/", http.StatusMovedPermanently) + cleanPath := path.Clean(prefix) + "/" + http.Redirect(w, r, cleanPath, http.StatusMovedPermanently) return }