Merge pull request #1012 from ortgit/master

Security fix: Validate for open redirect everywhere, not just in login()
This commit is contained in:
mdipierro
2015-07-02 06:40:12 -05:00
2 changed files with 7 additions and 4 deletions
+1
View File
@@ -58,3 +58,4 @@ HOWTO-web2py-devel
*.sublime-project
*.sublime-workspace
.idea/*
site-packages/
+6 -4
View File
@@ -1541,6 +1541,12 @@ class Auth(object):
next = current.request.vars._next
if isinstance(next, (list, tuple)):
next = next[0]
if next and self.settings.prevent_open_redirect_attacks:
# Prevent an attacker from adding an arbitrary url after the
# _next variable in the request.
items = next.split('/')
if '//' in next and items[2] != current.request.env.http_host:
next = None
return next
def _get_user_id(self):
@@ -2513,10 +2519,6 @@ class Auth(object):
### use session for federated login
snext = self.get_vars_next()
if snext and self.settings.prevent_open_redirect_attacks:
items = snext.split('/')
if '//' in snext and items[2] != request.env.http_host:
snext = None
if snext:
session._auth_next = snext