enhance policy validation by ensuring protected policies have authentication methods and defaulting to HTTPS in external URL construction

This commit is contained in:
Eduardo Silva
2026-03-16 21:05:16 -03:00
parent cf4674b933
commit 8418beb482
2 changed files with 9 additions and 0 deletions

View File

@@ -24,6 +24,8 @@ def get_session(request: Request) -> SessionRecord | None:
def build_external_url(request: Request, path: str, **params: str) -> str:
proto = request.headers.get("x-forwarded-proto", request.url.scheme)
if proto not in ("http", "https"):
proto = "https"
host = request.headers.get("host", request.url.netloc)
prefix = request.app.state.settings.external_path.rstrip("/")
query = urlencode({key: value for key, value in params.items() if value is not None})