From d71a01f4fcc4bb5ca040889694c94a07e52fa50e Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:48:02 +0300 Subject: Security: Reject backslashes in post-login redirect targets safeNext only refused a second leading slash, but browsers treat "/\evil.com" as "//evil.com", so ?next= was still an open redirect after login. No path of ours contains a backslash, so any one is refused. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/web/web_test.go | 11 +++++++++++ 1 file changed, 11 insertions(+) (limited to 'internal/web/web_test.go') diff --git a/internal/web/web_test.go b/internal/web/web_test.go index 42d3b3a..7f66085 100644 --- a/internal/web/web_test.go +++ b/internal/web/web_test.go @@ -1003,3 +1003,14 @@ func TestHTTPSAndTrustProxy(t *testing.T) { t.Errorf("clientIP without TRUST_PROXY = %q, want the peer", ip) } } + +func TestSafeNext(t *testing.T) { + for in, want := range map[string]string{ + "/b/alice/": "/b/alice/", "/dashboard?x=1": "/dashboard?x=1", + "//evil.com": "", `/\evil.com`: "", `/b/\x/`: "", "http://evil.com": "", "dashboard": "", "": "", + } { + if got := safeNext(in); got != want { + t.Errorf("safeNext(%q) = %q, want %q", in, got, want) + } + } +} -- cgit v1.2.3