fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: allow all URL forms in redirects - #711

Merged
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes
Sep 30, 2022
Merged

fix: allow all URL forms in redirects#711
hf merged 1 commit into
masterfrom
hf/allow-list-all-schemes

Conversation

@hf

@hfhf commented Sep 29, 2022

Copy link
Copy Markdown
Contributor

GoTrue limited wildcard redirect patterns only on http or https URLs. This presents a problem in mobile apps that have dynamic redirects back to their application.

See: #710.

@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

There was some discussion here on this issue: #99

This does open up the space to introduce a wider attack surface for mobile apps, although this is not as significant as it appears. On Android at least, apps can also listen to https URLs too. It is up to the user of GoTrue to make sure their settings are secure when they add redirect patterns.

cc @kangmingtay@awalias

@hf
hfforce-pushed the hf/allow-list-all-schemes branch from d49dbcc to 1316be2CompareSeptember 30, 2022 08:30
@hf
hfforce-pushed the hf/allow-list-all-schemes branch from 1316be2 to 4a691dfCompareSeptember 30, 2022 08:42
@hf

hf commented Sep 30, 2022

Copy link
Copy Markdown
ContributorAuthor

Added to Security doc (yet unpublished). Excerpt:


Redirect URLs

Supabase Auth lets you redirect back to different URLs on susccessful
authentication. Your client app can specify the URL to redirect back to using
the redirectTo parameter.

Given that in sophisticated attacks this parameter may come from a malicious
source, Supabase Auth implements an allow list which will be consulted prior to
sending a redirect response. Should the redirect parameter not fall in the URL
allow list, the Site URL is used.

The allow list can be a simple list of exactly matching URLs, but it also
supports wildcard characters to match them as a pattern.

:::tip
You can configure the URL allow list in the Authentcation General Settings
page
under Redirect URLs.
:::

Because wildcard patterns are also supported, you need to be careful when using
them, as you may be opening up your application to a larger attack surface.
Here are some examples of do's and don'ts.

Dont's.

  • **
    This pattern would match any redirect URL.
  • com.mobile.app.*://**
    This pattern would match any iOS application with a package name that starts
    with com.mobile.app.. An attacker can use this to call on those apps in a
    user's device.
  • https://*.com/**
    This pattern would match any URL on the .com domain name. An attacker can use
    this to redirect back to any website they control.

Dos.

  • https://app.example.com/**
    This is the recommended form for most project use cases on the web. Any
    redirects to the app.example.com domain will be allowed with any path. If
    your project needs to support multiple such domains, add multiple entries like
    this.
  • com.mobile.app://**
    This is the recommended form for most project use cases on iOS. Any redirects
    to the com.mobile.app application will be allowed with any path. If your
    project needs to support multiple applications, add multiple entries. Avoid
    using wildcards in the URL scheme!

:::tip
If you use exact or very specific URLs, make sure you always include a trailing
slash / as that is the proper valid form of URLs. Correct form:
https://app.example.com/*/sign-in/. Incorrect form:
https://app.example.com/*/sign-in.
:::

@hf
hf merged commit 4ece9e3 into masterSep 30, 2022
@hf
hf deleted the hf/allow-list-all-schemes branch September 30, 2022 09:05
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 2.17.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

uxodb pushed a commit to uxodb/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 13, 2024
LashaJini pushed a commit to LashaJini/auth that referenced this pull request Nov 15, 2024
cemalkilic pushed a commit that referenced this pull request Aug 7, 2025
xeladotbe pushed a commit to xeladotbe/supabase-auth that referenced this pull request Sep 27, 2025
fadymak pushed a commit that referenced this pull request Sep 30, 2025
@coderabbitaicoderabbitaiBot mentioned this pull request Apr 20, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hf@kangmingtay