Test for [email protected]/...
, http://example.com/?...
, and http://example.com/#
URLs in OpenRedirect
#78
Labels
[email protected]/...
, http://example.com/?...
, and http://example.com/#
URLs in OpenRedirect
#78
Test whether we can disable the URL hostname prefix using a
@
character (which makes everything after the scheme but before the@
character as the authorization), or disabling the URL suffix using?
(indicates beginning of the query string) or#
(indicates beginning of URL fragment) characters. This may require adding additional keyword arguments toOpenRedirect#initialize
to control whether@
,?
,#
are added to the test URL.http://[email protected]/evil/path
http://evil.com/?/valid/path
http://evil.com/#/valid/path
The text was updated successfully, but these errors were encountered: