aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/web_test.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:48:02 +0300
committergrm <grm@eyesin.space>2026-09-18 13:48:02 +0300
commitd71a01f4fcc4bb5ca040889694c94a07e52fa50e (patch)
treee3b48bb3fa6d40c8bae171fc48f51907de5fbf78 /internal/web/web_test.go
parent3eeaa6d9a33f9294ade64c8ff26144fba86a379e (diff)
downloadblogspace-d71a01f4fcc4bb5ca040889694c94a07e52fa50e.tar.gz
blogspace-d71a01f4fcc4bb5ca040889694c94a07e52fa50e.tar.bz2
blogspace-d71a01f4fcc4bb5ca040889694c94a07e52fa50e.zip
Security: Reject backslashes in post-login redirect targets
safeNext only refused a second leading slash, but browsers treat "/\evil.com" as "//evil.com", so ?next= was still an open redirect after login. No path of ours contains a backslash, so any one is refused. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/web_test.go')
-rw-r--r--internal/web/web_test.go11
1 files changed, 11 insertions, 0 deletions
diff --git a/internal/web/web_test.go b/internal/web/web_test.go
index 42d3b3a..7f66085 100644
--- a/internal/web/web_test.go
+++ b/internal/web/web_test.go
@@ -1003,3 +1003,14 @@ func TestHTTPSAndTrustProxy(t *testing.T) {
t.Errorf("clientIP without TRUST_PROXY = %q, want the peer", ip)
}
}
+
+func TestSafeNext(t *testing.T) {
+ for in, want := range map[string]string{
+ "/b/alice/": "/b/alice/", "/dashboard?x=1": "/dashboard?x=1",
+ "//evil.com": "", `/\evil.com`: "", `/b/\x/`: "", "http://evil.com": "", "dashboard": "", "": "",
+ } {
+ if got := safeNext(in); got != want {
+ t.Errorf("safeNext(%q) = %q, want %q", in, got, want)
+ }
+ }
+}