Skip to content

Conversation

@BorisPolonsky
Copy link

增加默认登陆方式中login_url的域名校验demo,实现默认登陆仅允许同域名跳转,避免开放重定向风险。

redirect(request.referer)操作也存在开放重定向风险,但考虑到可通过配置istio解决,不对代码作改动。

@BorisPolonsky BorisPolonsky changed the title 修复登陆页面的开放重定向 优化登陆页面的开放重定向问题 Sep 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant