validateAuthorizationUrl function
Checks the URL the API told us to open before it is handed to the system browser.
This is the value that decides which site the user is asked to type their
Google password into, and it arrives over the network. Every other URL that
crosses a trust boundary in this package is checked - validateSsoRedirectUri
for the callback, assertSameOrigin for a download URL, Config for the API
URL itself - and this one was not, so a compromised or misconfigured API could
point the sign-in sheet anywhere, or hand over a non-http scheme entirely.
Throws a FormatException rather than an ArgumentError: the caller supplied nothing here, the server did.
Implementation
String validateAuthorizationUrl(dynamic authorizationUrl) {
if (authorizationUrl is! String || authorizationUrl.isEmpty) {
throw const FormatException(
'The SSO start response carried no "authorizationUrl"',
);
}
final uri = Uri.tryParse(authorizationUrl);
if (uri == null || uri.host.isEmpty || uri.scheme != 'https') {
throw FormatException(
'The SSO provider must be reached over https, got: $authorizationUrl',
);
}
return authorizationUrl;
}