TASK: make it possible to redirect to an url provided by a get param#30
Open
kabarakh wants to merge 1 commit intosandstorm:masterfrom
Open
TASK: make it possible to redirect to an url provided by a get param#30kabarakh wants to merge 1 commit intosandstorm:masterfrom
kabarakh wants to merge 1 commit intosandstorm:masterfrom
Conversation
cb586b9 to
ce4e2c6
Compare
You can use this to forward to the referrer of the login form
ce4e2c6 to
a3de56d
Compare
Contributor
|
Hallo @skurfuerst, @beheist, mag sich das mal jemand anschauen? |
Member
|
@daniellienert was denkst du, müssen wir das mit nem Token absichern; könnte das sonst ne Sicherheitslücke sein? |
Contributor
|
Mir fallen nicht viele Angriffsvektoren ein. Eventuell direktes Umleiten eines Benutzers auf eine Seite mit Schadcode nach dem er sich eingeloggt hat. Was hälst du davon, nur Zieladressen zuzulassen, welche der aktuellen Domain entsprechen? |
Member
|
@daniellienert das find ich ne gute Idee :) 👍 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
You can use this to forward to the referrer of the login form