You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is a specific problem in scenarios where the Referrer header is not present (browser settings or via Referrer-Policy header).
The app falls back to previous URL tracked in the session, but this may not reflect an actual user page.
An example of this is secure images. Also relevant is #4649.
This leads to users being redirected to odd endpoints in such scenarios.
We could potentially override session or redirect handling to not track undesireable URLs.
Alternatively, we could avoid using the in-built back redirection within BookStack for an alternative option. As an example, we could provide the redirect path within the request (some care to be taken here to prevent open redirection).
Potentially revert the changes in ea0469e once done to allow PWA manifest personalisation.
The text was updated successfully, but these errors were encountered:
This is a specific problem in scenarios where the
Referrer
header is not present (browser settings or viaReferrer-Policy
header).The app falls back to previous URL tracked in the session, but this may not reflect an actual user page.
An example of this is secure images. Also relevant is #4649.
This leads to users being redirected to odd endpoints in such scenarios.
We could potentially override session or redirect handling to not track undesireable URLs.
Alternatively, we could avoid using the in-built back redirection within BookStack for an alternative option. As an example, we could provide the redirect path within the request (some care to be taken here to prevent open redirection).
Potentially revert the changes in ea0469e once done to allow PWA manifest personalisation.
The text was updated successfully, but these errors were encountered: