Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Security] Allow redirect after login to absolute URLs#47069

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
fabpot merged 1 commit intosymfony:4.4fromUFTimmy:ticket_46533
Jul 29, 2022

Conversation

@UFTimmy
Copy link

QA
Branch?4.4
Bug fix?yes
New feature?no
Deprecations?no
TicketsFix#46533
LicenseMIT
Doc PR

Fixes the regression introduced by#46317, and once again allows absolute URLs to be the target of authentication redirection, as specified in the documentation (https://symfony.com/doc/current/security/form_login.html#changing-the-default-page)

pableu reacted with thumbs up emoji
Copy link

@RomaixnRomaixn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Hello, I just tested this in a real project and it's works well ! :)

UFTimmy reacted with heart emoji
Copy link
Member

@nicolas-grekasnicolas-grekas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

This PR is correct.
Of course, we should not allow redirecting to any URL, but this is already guarded since#24995 (seeCVE-2017-16652)

@fabpot
Copy link
Member

Thank you@UFTimmy.

@fabpotfabpot merged commitdfa765d intosymfony:4.4Jul 29, 2022
This was referencedJul 29, 2022
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@fabpotfabpotfabpot approved these changes

@nicolas-grekasnicolas-grekasnicolas-grekas approved these changes

@wouterjwouterjAwaiting requested review from wouterjwouterj is a code owner

@chalasrchalasrAwaiting requested review from chalasrchalasr is a code owner

+1 more reviewer

@RomaixnRomaixnRomaixn approved these changes

Reviewers whose approvals may not affect merge requirements

Assignees

No one assigned

Projects

None yet

Milestone

4.4

Development

Successfully merging this pull request may close these issues.

5 participants

@UFTimmy@fabpot@nicolas-grekas@Romaixn@carsonbot

[8]ページ先頭

©2009-2025 Movatter.jp