Skip to content

fix(login): redirect-url could contain a | that was parsed server-side#469

Merged
TrueBrain merged 1 commit intomainfrom
dont-allow-parser-function-in-login-redirect
Jun 7, 2023
Merged

fix(login): redirect-url could contain a | that was parsed server-side#469
TrueBrain merged 1 commit intomainfrom
dont-allow-parser-function-in-login-redirect

Conversation

@TrueBrain
Copy link
Copy Markdown
Owner

Users do the weirdest things.

Import to note: there is no security impact based on this, as the same could be achieved by editing a page (which everyone can). It still had to obey the same rules, and was still sandboxed in full.

It was just weird.

Users do the weirdest things.

Import to note: there is no security impact based on this, as the
same could be achieved by editing a page (which everyone can). It
still had to obey the same rules, and was still sandboxed in full.

It was just weird.
@TrueBrain TrueBrain merged commit e88f77e into main Jun 7, 2023
@TrueBrain TrueBrain deleted the dont-allow-parser-function-in-login-redirect branch June 7, 2023 09:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant