Open redirect attacks should be caught for all functions that use the _next variable (for example: logout()) instead of just for the login() function.
This commit is contained in:
+6
-4
@@ -1541,6 +1541,12 @@ class Auth(object):
|
|||||||
next = current.request.vars._next
|
next = current.request.vars._next
|
||||||
if isinstance(next, (list, tuple)):
|
if isinstance(next, (list, tuple)):
|
||||||
next = next[0]
|
next = next[0]
|
||||||
|
if next and self.settings.prevent_open_redirect_attacks:
|
||||||
|
# Prevent an attacker from adding an arbitrary url after the
|
||||||
|
# _next variable in the request.
|
||||||
|
items = next.split('/')
|
||||||
|
if '//' in next and items[2] != current.request.env.http_host:
|
||||||
|
next = None
|
||||||
return next
|
return next
|
||||||
|
|
||||||
def _get_user_id(self):
|
def _get_user_id(self):
|
||||||
@@ -2513,10 +2519,6 @@ class Auth(object):
|
|||||||
|
|
||||||
### use session for federated login
|
### use session for federated login
|
||||||
snext = self.get_vars_next()
|
snext = self.get_vars_next()
|
||||||
if snext and self.settings.prevent_open_redirect_attacks:
|
|
||||||
items = snext.split('/')
|
|
||||||
if '//' in snext and items[2] != request.env.http_host:
|
|
||||||
snext = None
|
|
||||||
|
|
||||||
if snext:
|
if snext:
|
||||||
session._auth_next = snext
|
session._auth_next = snext
|
||||||
|
|||||||
Reference in New Issue
Block a user