Merged
Conversation
d2324db to
7806462
Compare
mike-burns
approved these changes
Aug 31, 2021
Contributor
mike-burns
left a comment
There was a problem hiding this comment.
Thanks for taking this on.
An open redirect can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected the external domain that comes after the slashes (http://example.com). To fix this issue, extra sanitization was added when processing the return_to url, removing multiple leading slashes to avoid the open redirect. Co-authored-by: Kirill Efimov <[email protected]>
7806462 to
4372c38
Compare
adafairweather
added a commit
to Silversheet/clearance
that referenced
this pull request
Jan 10, 2022
thoughtbot#945 Since we're stuck on Rails 4 for a while yet, we are adding this fix to an earlier, compatible version of clearance for our own use.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
An open redirect can be possible when users are able to set the value of
session[:return_to]. If the value used for return_to contains multiple
leading slashes (/////example.com) the user ends up being redirected the
external domain that comes after the slashes (http://example.com).
To fix this issue, extra sanitization was added when processing the
return_to url, removing multiple leading slashes to avoid the open
redirect.