-
- Downloads
Merge branch 'security-fix-uri-xss-applications-11-3' into 'security-11-3'
[11.3] Reflected XSS in OAuth Authorize window due to redirect_uri allowing arbitrary protocols See merge request gitlab/gitlabhq!2581
No related branches found
No related tags found
Showing
- app/controllers/oauth/applications_controller.rb 1 addition, 1 deletionapp/controllers/oauth/applications_controller.rb
- changelogs/unreleased/security-fix-uri-xss-applications.yml 5 additions, 0 deletionschangelogs/unreleased/security-fix-uri-xss-applications.yml
- config/initializers/doorkeeper.rb 7 additions, 0 deletionsconfig/initializers/doorkeeper.rb
- db/post_migrate/20181026091631_migrate_forbidden_redirect_uris.rb 32 additions, 0 deletions...migrate/20181026091631_migrate_forbidden_redirect_uris.rb
- spec/controllers/oauth/applications_controller_spec.rb 17 additions, 0 deletionsspec/controllers/oauth/applications_controller_spec.rb
- spec/migrations/migrate_forbidden_redirect_uris_spec.rb 48 additions, 0 deletionsspec/migrations/migrate_forbidden_redirect_uris_spec.rb
- spec/requests/api/applications_spec.rb 11 additions, 1 deletionspec/requests/api/applications_spec.rb
Please register or sign in to comment