Skip to content

block protocol-relative URLs in login redirect#253

Merged
cmyui merged 1 commit intoosuAkatsuki:masterfrom
raya-ac:fix/open-redirect-login
Apr 3, 2026
Merged

block protocol-relative URLs in login redirect#253
cmyui merged 1 commit intoosuAkatsuki:masterfrom
raya-ac:fix/open-redirect-login

Conversation

@raya-ac
Copy link
Copy Markdown
Contributor

@raya-ac raya-ac commented Apr 3, 2026

Fixes #248

Added a check for // prefix so redir=//evil.com gets rejected.

@cmyui cmyui merged commit dfd0e9a into osuAkatsuki:master Apr 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Open redirect via protocol-relative URL in login

2 participants