Skip to content

Conversation

@jeremystretch
Copy link
Member

Fixes: #19346

  • Introduce the safe_for_redirect() utility function
  • Ensure it's used to wrap all redirect URLs that could potentially contain user-originated data

@jeremystretch jeremystretch marked this pull request as ready for review April 28, 2025 18:44
@jeremystretch jeremystretch requested review from a team and bctiemann and removed request for a team April 28, 2025 18:44
@bctiemann bctiemann merged commit c0e6168 into main Apr 30, 2025
10 checks passed
@jeremystretch jeremystretch deleted the 19346-redirect-checks branch April 30, 2025 18:06
@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 31, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Redirect URLs are not sanitized in some cases

3 participants