Skip to content

Validate intended login redirects - #378

Merged
Cannonb4ll merged 2 commits into
ploi:mainfrom
bjarn:codex/validate-login-intended-url
Oct 5, 2026
Merged

Cannonb4ll merged 2 commits into
ploi:mainfrom
bjarn:codex/validate-login-intended-url

Conversation

@bjarn

@bjarn bjarn commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Accept local paths and same-origin HTTP or HTTPS URLs only.
  • Reject external, protocol-relative, malformed, and non-HTTP destinations.
  • Clear an unsafe intended URL from the session.
  • Add redirect regression tests.

Security impact

A crafted login link could redirect a user to an external site after authentication.

Tests

  • php artisan test --compact tests/Feature/Auth/LoginTest.php

@Cannonb4ll
Cannonb4ll merged commit 7c1891c into ploi:main Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants