Skip to content

Commit 0b964b6

Browse files
authored
Merge pull request #163 from fredrikstave/master
Sanitize response message for unathorized headers
2 parents 765b62a + 80fc71a commit 0b964b6

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

EventListener/CorsListener.php

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -176,8 +176,9 @@ protected function getPreflightResponse(Request $request, array $options): Respo
176176
continue;
177177
}
178178
if (!in_array($header, $options['allow_headers'], true)) {
179+
$sanitizedMessage = htmlentities('Unauthorized header '.$header, ENT_QUOTES, 'UTF-8');
179180
$response->setStatusCode(400);
180-
$response->setContent('Unauthorized header '.$header);
181+
$response->setContent($sanitizedMessage);
181182
break;
182183
}
183184
}

0 commit comments

Comments
 (0)