From e6271dd5f111edf817eeafb1d71f88f4009f9850 Mon Sep 17 00:00:00 2001 From: mdipierro Date: Tue, 23 Jul 2013 02:06:42 -0500 Subject: [PATCH] fixed possible _next vulnerability --- VERSION | 2 +- gluon/tools.py | 7 ++++++- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/VERSION b/VERSION index e1bfa671..1e9bc0d6 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -Version 2.6.0-development+timestamp.2013.07.23.01.03.38 +Version 2.6.0-development+timestamp.2013.07.23.02.04.35 diff --git a/gluon/tools.py b/gluon/tools.py index 59747ce6..dced42c2 100644 --- a/gluon/tools.py +++ b/gluon/tools.py @@ -2046,7 +2046,12 @@ class Auth(object): ### pass if next is DEFAULT: - next = self.next or self.settings.login_next + # important for security + next = self.settings.login_next + if self.next: + host = self.next.split('//',1)[-1].split('/')[0] + if host in self.settings.cas_domains: + next = self.next if onvalidation is DEFAULT: onvalidation = self.settings.login_onvalidation if onaccept is DEFAULT: