Affected by GO-2022-0783
and 4 other vulnerabilities
GO-2022-0783 : JWT leak via Open Redirect in Programmatic access in github.com/pomerium/pomerium
GO-2022-0933 : Incorrect handling of H2 GOAWAY + SETTINGS frames in github.com/pomerium/pomerium
GO-2023-1800 : Pomerium vulnerable to Incorrect Authorization with specially crafted requests in github.com/pomerium/pomerium
GO-2024-2965 : Pomerium exposed OAuth2 access and ID tokens in user info endpoint response in github.com/pomerium/pomerium
GO-2024-3179 : Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium
Discover Packages
github.com/pomerium/pomerium
internal
urlutil
package
Version:
v0.3.0
Opens a new window with list of versions in this module.
Published: Sep 1, 2019
License: Apache-2.0
Opens a new window with license information.
Imports: 3
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
Documentation
¶
ParseAndValidateURL wraps standard library's default url.Parse because
it's much more lenient about what type of urls it accepts than pomerium.
StripPort returns a host, without any port number.
If Host is an IPv6 literal with a port number, Hostname returns the
IPv6 literal without the square brackets. IPv6 literals may include
a zone identifier.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.