mirror of
https://github.com/steveiliop56/tinyauth.git
synced 2026-01-19 13:52:29 +00:00
fix: ensure safe redirect check only accepts actual domains
This commit is contained in:
@@ -205,4 +205,9 @@ func TestIsRedirectSafe(t *testing.T) {
|
||||
redirectURL = "http://example.org/page"
|
||||
result = utils.IsRedirectSafe(redirectURL, domain)
|
||||
assert.Equal(t, false, result)
|
||||
|
||||
// Case with malicious domain
|
||||
redirectURL = "https://malicious-example.com/yoyo"
|
||||
result = utils.IsRedirectSafe(redirectURL, domain)
|
||||
assert.Equal(t, false, result)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user