validateAuthorizationUrl function

String validateAuthorizationUrl(
  1. dynamic authorizationUrl
)

Checks the URL the API told us to open before it is handed to the system browser.

This is the value that decides which site the user is asked to type their Google password into, and it arrives over the network. Every other URL that crosses a trust boundary in this package is checked - validateSsoRedirectUri for the callback, assertSameOrigin for a download URL, Config for the API URL itself - and this one was not, so a compromised or misconfigured API could point the sign-in sheet anywhere, or hand over a non-http scheme entirely.

Throws a FormatException rather than an ArgumentError: the caller supplied nothing here, the server did.

Implementation

String validateAuthorizationUrl(dynamic authorizationUrl) {
  if (authorizationUrl is! String || authorizationUrl.isEmpty) {
    throw const FormatException(
      'The SSO start response carried no "authorizationUrl"',
    );
  }

  final uri = Uri.tryParse(authorizationUrl);
  if (uri == null || uri.host.isEmpty || uri.scheme != 'https') {
    throw FormatException(
      'The SSO provider must be reached over https, got: $authorizationUrl',
    );
  }

  return authorizationUrl;
}