Re: zope.pluggableauth and "camefrom" information in login form not an absolute URL

Jan-Wijbrand Kolman <[email protected]>
Newsgroups gmane.comp.web.zope.devel
Message-ID <[email protected]>
On 2/7/11 12:04 PM, Adam GROSZER wrote:
> Hello,
>
> I'm not sure whether you open up a security hole there.
> Imagine that someone does a
> http://yoursite.com/@@loginform.html?camefrom=http://mysite.com
> We ended up with storing the camefrom URL in a session variable.

The redirect method in the zope publisher checks whether the redirect is 
"trusted" to go to a different host. The trusted arguments is "False" by 
default. I think will catch this situation just fine. Or doesn't it?

regards, jw

_______________________________________________
Zope-Dev maillist  -  [email protected]
https://mail.zope.org/mailman/listinfo/zope-dev
**  No cross posts or HTML encoding!  **
(Related lists - 
 https://mail.zope.org/mailman/listinfo/zope-announce
 https://mail.zope.org/mailman/listinfo/zope )
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.