#11457: Login Redirect Security Check Overly Broad
----------------------------------------+-----------------------------------
          Reporter:  dnag...@gmail.com  |         Owner:  Quis                  
  
            Status:  assigned           |     Milestone:  1.2                   
  
         Component:  Authentication     |       Version:  1.0                   
  
        Resolution:                     |      Keywords:  auth login redirect 
next
             Stage:  Ready for checkin  |     Has_patch:  1                     
  
        Needs_docs:  0                  |   Needs_tests:  0                     
  
Needs_better_patch:  1                  |  
----------------------------------------+-----------------------------------
Changes (by Quis):

  * owner:  nobody => Quis
  * needs_better_patch:  0 => 1
  * status:  new => assigned

Comment:

 Shouldn't you check for other protocols? https:// can be used exactly the
 same as http..

-- 
Ticket URL: <http://code.djangoproject.com/ticket/11457#comment:5>
Django <http://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To post to this group, send email to django-upda...@googlegroups.com.
To unsubscribe from this group, send email to 
django-updates+unsubscr...@googlegroups.com.
For more options, visit this group at 
http://groups.google.com/group/django-updates?hl=en.

Reply via email to