diff --git a/package.json b/package.json index 9dd87f1..ec71490 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "ipwhitelist", - "version": "0.5.174", + "version": "0.5.175", "description": "IP WhiteList microservice for cloud provider", "main": "server.js", "scripts": { diff --git a/server.js b/server.js index 8df0035..62f97c3 100644 --- a/server.js +++ b/server.js @@ -109,7 +109,7 @@ async function start() { ? (err.stack || err.message || String(err)) : JSON.stringify(err); console.error('Unhandled error:', ctx, detail); - res.status(500).send('Ошибка [' + ctx.url + '] user=' + ctx.user + ' clientId=' + ctx.clientId + ' — ' + detail.slice(0, 500)); + res.status(500).send('Внутренняя ошибка сервера'); }); // ── Старт сервера ───────────────────────────────────────────────────────────── diff --git a/src/auth.js b/src/auth.js index d0c0dfb..3b998f1 100644 --- a/src/auth.js +++ b/src/auth.js @@ -528,7 +528,7 @@ function httpPost(url, body, headers) { * Защита от open redirect: //evil.com и https://evil.com → '/'. */ function safeReturn(target) { - if (typeof target === 'string' && target.startsWith('/') && !target.startsWith('//')) { + if (typeof target === 'string' && target.startsWith('/') && !target.startsWith('//') && target[1] !== '\\') { return target; } return '/'; diff --git a/v2/src/config/index.js b/v2/src/config/index.js index 82b0293..d8b23bb 100644 --- a/v2/src/config/index.js +++ b/v2/src/config/index.js @@ -8,7 +8,7 @@ // ═══════════════════════════════════════════════════════════════════════════════ module.exports = { - version: '0.5.174', + version: '0.5.175', // ── IAM ────────────────────────────────────────────────────────────────── iamUrl: process.env.V2_IAM_URL || 'https://auth-api.ngcloud.ru/api/v1/auth/user',