feat(login-flow-v2): Restrict allowed apps by user agent check #50650
+192
−1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
add config value to
config.php
:or via occ
./occ config:system:set core.login_flow_v2.allowed_user_agents 0 --value '/Custom Foo/i'
Test Allowed client
click on generated
login
url.Test Forbidden client
click on generated
![Selection_20250204-003](https://private-user-images.githubusercontent.com/145785698/409967751-93a0a111-abc7-423e-8db2-4dbc4fc6a205.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkzODEzMTIsIm5iZiI6MTczOTM4MTAxMiwicGF0aCI6Ii8xNDU3ODU2OTgvNDA5OTY3NzUxLTkzYTBhMTExLWFiYzctNDIzZS04ZGIyLTRkYmM0ZmM2YTIwNS5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjEyJTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIxMlQxNzIzMzJaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT05NjdjYTliNDY1MTRhMGNmNWE5NjljOWQ5MTE2NmEwNTNmNjc3MDk5NTJiMmM2ZTk3ZjNjMjZmNDM5N2Y3ZGJmJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.C7ANBKAO8WFqaglknxawJzWTmPi_4f-y4wguL3XCRu0)
login
url.observe
Unitests
phpunit-autotest-core.xml
filephpunit-autotest-core.xml
Checklist