mirror of
https://github.com/mattermost/mattermost.git
synced 2026-09-24 16:05:00 +08:00
Mattermost Server OAuth Flow Cross-Site Scripting (#17743)
Automatic Merge
This commit is contained in:
+2
-1
@@ -4,6 +4,7 @@
|
||||
package web
|
||||
|
||||
import (
|
||||
"html"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"path/filepath"
|
||||
@@ -384,7 +385,7 @@ func mobileLoginWithOAuth(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
redirectURL := r.URL.Query().Get("redirect_to")
|
||||
redirectURL := html.EscapeString(r.URL.Query().Get("redirect_to"))
|
||||
|
||||
if redirectURL != "" && !utils.IsValidMobileAuthRedirectURL(c.App.Config(), redirectURL) {
|
||||
err := model.NewAppError("mobileLoginWithOAuth", "api.invalid_custom_url_scheme", nil, "", http.StatusBadRequest)
|
||||
|
||||
+2
-1
@@ -5,6 +5,7 @@ package web
|
||||
|
||||
import (
|
||||
b64 "encoding/base64"
|
||||
"html"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"strings"
|
||||
@@ -35,7 +36,7 @@ func loginWithSaml(c *Context, w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
action := r.URL.Query().Get("action")
|
||||
isMobile := action == model.OAUTH_ACTION_MOBILE
|
||||
redirectURL := r.URL.Query().Get("redirect_to")
|
||||
redirectURL := html.EscapeString(r.URL.Query().Get("redirect_to"))
|
||||
relayProps := map[string]string{}
|
||||
relayState := ""
|
||||
|
||||
|
||||
Reference in New Issue
Block a user