Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Web Login: Redirect URL should be prevented if the URL is not listed in application #223

Closed
kazemisoroush opened this issue Sep 17, 2021 · 3 comments · Fixed by #246
Closed
Assignees
Labels
enhancement New feature or request

Comments

@kazemisoroush
Copy link

https://www.loom.com/share/2dac76a762ff4b5d9b7df75ed9d37293

The google.com URL is not listed in the REDIRECT URLS in admin but Identifo successfully redirects to google.com after successful login.
image

@kazemisoroush
Copy link
Author

This is happening in v2.1.2

@erudenko erudenko self-assigned this Sep 17, 2021
@erudenko erudenko added the enhancement New feature or request label Sep 17, 2021
@erudenko
Copy link
Member

We need to check redirect URL and show error if it is wrong (empty or not listed) before letting user to log in

@kazemisoroush
Copy link
Author

@erudenko I think that deserves its separate task as it's a different issue.

sokolovstas added a commit that referenced this issue Oct 14, 2021
@sokolovstas sokolovstas linked a pull request Oct 14, 2021 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants