Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-2287

Redirect after logging out is not validating the redirect link thus allowing to redirect outside of the scope of Sling

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • Auth Core 1.0.6
    • Auth Core 1.1.0
    • Authentication
    • None

    Description

      After logging out the Sling Authenticator can be instructed to redirect to somewhere else. This link is not currently checked for validity.

      Thus it is possible to redirect to another site after logging out.

      The idea, though, is to redirect to another location inside the same site after logging out.

      Attachments

        Activity

          People

            fmeschbe Felix Meschberger
            fmeschbe Felix Meschberger
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: