Last modified: 2013-12-11 21:38:50 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T60305, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 58305 - Validate redirect destination in Wikimania Scholarships application
Validate redirect destination in Wikimania Scholarships application
Status: RESOLVED FIXED
Product: Wikimedia
Classification: Unclassified
Wikimania Scholarships (Other open bugs)
wmf-deployment
All All
: Highest normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks: 57546
  Show dependency treegraph
 
Reported: 2013-12-11 03:24 UTC by Bryan Davis
Modified: 2013-12-11 21:38 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Bryan Davis 2013-12-11 03:24:32 UTC
Security review feedback:

> Wikimania/Scholarship/Controllers/Login.php
> * handlePost - sanity check $next before you redirect
Comment 1 Gerrit Notification Bot 2013-12-11 04:16:13 UTC
Change 100750 had a related patch set uploaded by BryanDavis:
Validate redirect destination on login

https://gerrit.wikimedia.org/r/100750
Comment 2 Gerrit Notification Bot 2013-12-11 20:23:19 UTC
Change 100750 merged by jenkins-bot:
Validate redirect destination on login

https://gerrit.wikimedia.org/r/100750

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links