diff options
| author | winter Sparkles | 2026-08-09 16:39:47 +0100 |
|---|---|---|
| committer | winter Sparkles | 2026-08-09 16:39:47 +0100 |
| commit | f1019ef47772cecb29701332b64005a0f2031a24 (patch) | |
| tree | 41b326933efb417ed86872f96836df44ff974857 /routes/integration/auth-request.php | |
| parent | cf123326b13e2f648b0a1cca4d8d1c7264e2e5d8 (diff) | |
support non-redirecting domains for auth-request
Diffstat (limited to 'routes/integration/auth-request.php')
| -rw-r--r-- | routes/integration/auth-request.php | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/routes/integration/auth-request.php b/routes/integration/auth-request.php index 21c5d11..ba04988 100644 --- a/routes/integration/auth-request.php +++ b/routes/integration/auth-request.php @@ -23,6 +23,16 @@ function GET(array $config) { return; } + if (isset($_SERVER['HTTP_X_ORIGINAL_URI'])) { + $host = parse_url($_SERVER['HTTP_X_ORIGINAL_URI'], PHP_URL_HOST); + if (in_array( + $host, $config['integration']['no-redirect-domains'] ?? [] + )) { + // ok, don't redirect to login page + return; + } + } + http_response_code(401); $login = 'https://' . $config['site']['primary-domain'] . '/login'; if (isset($_SERVER['HTTP_X_ORIGINAL_URI'])) { |
