Merge pull request #1382 from apa-1/master

Fix next redirect if only one / exists
This commit is contained in:
mdipierro
2016-07-01 02:00:58 -05:00
committed by GitHub
+6 -4
View File
@@ -1918,10 +1918,12 @@ class Auth(object):
if isinstance(next, (list, tuple)): if isinstance(next, (list, tuple)):
next = next[0] next = next[0]
if next and self.settings.prevent_open_redirect_attacks: if next and self.settings.prevent_open_redirect_attacks:
# Prevent an attacker from adding an arbitrary url after the # Prevent an attacker from adding an arbitrary url after the _next variable in the request.
# _next variable in the request. # Browsers will fix a single / so check multiple things just in case
items = next.split('/') items = filter(None, next.split('/'))
if '//' in next and items[2] != current.request.env.http_host: has_url = any(x in next for x in ['//', ':', 'ftp', 'http', 'rss', 'xml'])
if has_url and len(items) > 1:
if items[1] != current.request.env.http_host:
next = None next = None
return next return next