diff --git a/dashboard/src/auth.rs b/dashboard/src/auth.rs index 4fc322b632604ce76585a6a5a07d9b368f22272d..fecc2df0fb97e991f6039153259330fe412805f0 100644 --- a/dashboard/src/auth.rs +++ b/dashboard/src/auth.rs @@ -705,21 +705,40 @@ pub async fn route(State(app): State>, request: Request) -> ResultSign out of Files
").into_response()); } - if method != Method::POST { + if method + != (if shale_logout { + Method::GET + } else { + Method::POST + }) + { return Err(Error::new(405, "Use the sign-out button.")); } - let expected = if path.contains("/file/") { + let expected = if shale_logout { + &app.shale.origin + } else if path.contains("/file/") { &auth.file } else { &auth.origin }; - if headers.get("origin").and_then(|v| v.to_str().ok()) - != Some(expected.origin().ascii_serialization().as_str()) - { + let source = if shale_logout { + headers + .get("referer") + .and_then(|v| v.to_str().ok()) + .and_then(|v| url::Url::parse(v).ok()) + .map(|v| v.origin().ascii_serialization()) + } else { + headers + .get("origin") + .and_then(|v| v.to_str().ok()) + .map(str::to_owned) + }; + if source.as_deref() != Some(expected.origin().ascii_serialization().as_str()) { return Err(Error::new(403, "Open your account to sign out.")); } if let Some(token) = cookie(&headers, COOKIE) { @@ -728,12 +747,19 @@ pub async fn route(State(app): State>, request: Request) -> Result