Skip to content

Commit de70ba9

Browse files
fix: guard against invalid origin header value (#5288)
1 parent ef7318f commit de70ba9

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

packages/start-server-core/src/createStartHandler.ts

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,10 @@ export function createStartHandler<TRegister = Register>(
9797
function getOrigin() {
9898
const originHeader = request.headers.get('Origin')
9999
if (originHeader) {
100-
return originHeader
100+
try {
101+
new URL(originHeader)
102+
return originHeader
103+
} catch {}
101104
}
102105
try {
103106
return new URL(request.url).origin

0 commit comments

Comments
 (0)