Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-9812

AccessManager Post servlets should not allow redirects to other hosts

    XMLWordPrintableJSON

Details

    Description

      Through the :redirect parameter of the AbstractAccessPostServlet arbitrary redirects are possible. That should be limited so that redirects to other servers are not possible.

       

      Expected: Apply the same solution that was applied to SlingPostServlet for SLING-4469 

      Attachments

        Activity

          People

            enorman Eric Norman
            enorman Eric Norman
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: