From 62fcc3974d3e6cb9da6328bf03567c787e01b885 Mon Sep 17 00:00:00 2001 From: Somdev Sangwan Date: Thu, 28 Jan 2021 16:23:23 +0530 Subject: [PATCH] added underscore bypass --- core/tests.py | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/core/tests.py b/core/tests.py index bda5017..e0881e4 100644 --- a/core/tests.py +++ b/core/tests.py @@ -62,6 +62,15 @@ def active_tests(url, root, scheme, header_dict, delay): return {url : info} time.sleep(delay) + headers = requester(url, scheme, header_dict, root + '_.example.com') + acao_header, acac_header = headers['access-control-allow-origin'], headers.get('access-control-allow-credentials', None) + if acao_header and '_.example.com' in acao_header: + info = details['unrecognized underscore'] + info['acao header'] = acao_header + info['acac header'] = acac_header + return {url : info} + time.sleep(delay) + headers = requester(url, scheme, header_dict, root + '%60.example.com') acao_header, acac_header = headers['access-control-allow-origin'], headers.get('access-control-allow-credentials', None) if acao_header and '`.example.com' in acao_header: