Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent attackers from submitting illegal return URLs #93

Merged
merged 1 commit into from Sep 30, 2015

Conversation

rjkip
Copy link
Contributor

@rjkip rjkip commented Sep 30, 2015

Before this change, a return URL of https://selfservice.tld@attack.tld
was acceptable, because it started with our app's HTTP scheme and
host.

Addresses Security Audit 5.2.12.

Before this change, a return URL of https://selfservice.tld@attack.tld
was acceptable, because it started with our app's HTTP scheme and
host.
@DRvanR
Copy link
Contributor

DRvanR commented Sep 30, 2015

👍

rjkip added a commit that referenced this pull request Sep 30, 2015
…ecurity

Prevent attackers from submitting illegal return URLs
@rjkip rjkip merged commit 1ba8b77 into develop Sep 30, 2015
@rjkip rjkip deleted the bugfix/locale-switch-return-url-security branch September 30, 2015 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants