We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
The function respondToExitIframeRequest will redirect to any URL passed in the exitIframe parameter.
respondToExitIframeRequest
exitIframe
We could simply check that the exitIframe parameter ends with .myshopify.com to limit the possibilities of open redirects.
.myshopify.com
Note: I didn't report this as a security vulnerability as open redirects are ineligible.
The text was updated successfully, but these errors were encountered:
No branches or pull requests
The function
respondToExitIframeRequest
will redirect to any URL passed in theexitIframe
parameter.We could simply check that the
exitIframe
parameter ends with.myshopify.com
to limit the possibilities of open redirects.Note: I didn't report this as a security vulnerability as open redirects are ineligible.
The text was updated successfully, but these errors were encountered: