···268268 Some(parent_host),
269269 );
270270 }
271271+ if let Some(ref app) = params.app {
272272+ if !allowed_hosts.contains(app) {
273273+ return err("Login is not allowed for this app", false, Some(app));
274274+ }
275275+ }
271276 let parent_origin = url.origin().ascii_serialization();
272277 if parent_origin == "null" {
273278 return err("Origin or referrer header value is opaque", true, None);