##// END OF EJS Templates
login: simplify came_from validation...
login: simplify came_from validation Even though only server-relative came_from URLs were ever generated, the login controller allowed fully qualified URLs (URLs including scheme and server). To avoid an open HTTP redirect (CWE-601), the code included logic to prevent redirects to other servers. By requiring server-relative URLs, this logic can simply be removed. Note: SCRIPT_NAME is still not validated and it is thus possible to redirect from one app to another on the same netloc.
Søren Løvborg -
r5510:a0a9ae75 stable
Show More
Name Size Modified Last Commit Author
/ scripts
make-release Loading ...
manifest Loading ...