Mattermost Server OAuth Flow Cross-Site Scripting (#17743)

Automatic Merge
This commit is contained in:
Anurag Shivarathri
2021-06-10 14:10:22 +02:00
committed by GitHub
parent 364ea5ed63
commit c898c3007f
2 changed files with 4 additions and 2 deletions
+2 -1
View File
@@ -4,6 +4,7 @@
package web
import (
"html"
"net/http"
"net/url"
"path/filepath"
@@ -384,7 +385,7 @@ func mobileLoginWithOAuth(c *Context, w http.ResponseWriter, r *http.Request) {
return
}
redirectURL := r.URL.Query().Get("redirect_to")
redirectURL := html.EscapeString(r.URL.Query().Get("redirect_to"))
if redirectURL != "" && !utils.IsValidMobileAuthRedirectURL(c.App.Config(), redirectURL) {
err := model.NewAppError("mobileLoginWithOAuth", "api.invalid_custom_url_scheme", nil, "", http.StatusBadRequest)
+2 -1
View File
@@ -5,6 +5,7 @@ package web
import (
b64 "encoding/base64"
"html"
"net/http"
"strconv"
"strings"
@@ -35,7 +36,7 @@ func loginWithSaml(c *Context, w http.ResponseWriter, r *http.Request) {
}
action := r.URL.Query().Get("action")
isMobile := action == model.OAUTH_ACTION_MOBILE
redirectURL := r.URL.Query().Get("redirect_to")
redirectURL := html.EscapeString(r.URL.Query().Get("redirect_to"))
relayProps := map[string]string{}
relayState := ""