Skip to content
Snippets Groups Projects
Select Git revision
  • master default protected
  • 12-9-stable
  • 12-7-stable
  • 12-6-stable
  • 12-8-stable
  • github/fork/Kloppi313/patch-1
  • 12-5-stable
  • 12-4-stable
  • github/fork/ramalokesh8477/master
  • 12-1-stable
  • 12-2-stable
  • 12-0-stable
  • 12-3-stable
  • 42-42-stable
  • github/fork/hussamgit398/patch-2
  • 12-3-auto-deploy-20190911
  • 12-3-auto-deploy-20190916
  • 12-3-auto-deploy-20190908
  • 12-3-auto-deploy-20190901
  • 12-3-auto-deploy-20190901-32664
  • v12.10.0.pre
  • v12.9.0
  • v12.9.0-rc42
  • v12.8.7
  • v12.8.6
  • v12.8.5
  • v12.8.4
  • v12.8.3
  • v12.6.8
  • v12.7.7
  • v12.8.2
  • v12.8.1
  • v12.9.0.pre
  • v12.8.0
  • v12.8.0-rc42
  • v12.5.10
  • v12.7.6
  • v12.6.7
  • v12.7.5
  • v12.5.9
40 results

sessions_controller.rb

  • Bob Van Landuyt's avatar
    39916fdf
    Reuses `InternalRedirect` when possible · 39916fdf
    Bob Van Landuyt authored
    `InternalRedirect` prevents Open redirect issues by only allowing
    redirection to paths on the same host.
    
    It cleans up any unwanted strings from the path that could point to
    another host (fe. //about.gitlab.com/hello). While preserving the
    querystring and fragment of the uri.
    
    It is already used by:
    
    - `TermsController`
    - `ContinueParams`
      - `ImportsController`
      - `ForksController`
    - `SessionsController`: Only for verifying the host in CE. EE allows
       redirecting to a different instance using Geo.
    39916fdf
    History
    Reuses `InternalRedirect` when possible
    Bob Van Landuyt authored
    `InternalRedirect` prevents Open redirect issues by only allowing
    redirection to paths on the same host.
    
    It cleans up any unwanted strings from the path that could point to
    another host (fe. //about.gitlab.com/hello). While preserving the
    querystring and fragment of the uri.
    
    It is already used by:
    
    - `TermsController`
    - `ContinueParams`
      - `ImportsController`
      - `ForksController`
    - `SessionsController`: Only for verifying the host in CE. EE allows
       redirecting to a different instance using Geo.