#11457: Login Redirect Security Check Overly Broad
----------------------------------------+-----------------------------------
          Reporter:  [email protected]  |         Owner:                        
  
            Status:  new                |     Milestone:  1.2                   
  
         Component:  Authentication     |       Version:  1.0                   
  
        Resolution:                     |      Keywords:  auth login redirect 
next
             Stage:  Ready for checkin  |     Has_patch:  1                     
  
        Needs_docs:  0                  |   Needs_tests:  0                     
  
Needs_better_patch:  0                  |  
----------------------------------------+-----------------------------------
Comment (by brutasse):

 With the regex you suggest, the tests doesn't pass.

 If you call /login/?next=http%3A//example.com, the redirection should be
 blocked (this URL matches the not_secure pattern). If you call
 /login/?next=/view/?param=http%3A//example.com, then it is fine to
 redirect to /view/?param=http%3A//example.com (there is a '/' before
 http://example.com that makes it a safe URL to redirect to).

-- 
Ticket URL: <http://code.djangoproject.com/ticket/11457#comment:9>
Django <http://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/django-updates?hl=en.

Reply via email to