From f8c5e4f91f848f1f29dcbb55584d5bb8d4441874 Mon Sep 17 00:00:00 2001 From: Matt Walston Date: Sun, 20 Jan 2019 20:10:49 -0500 Subject: [PATCH] fix unsafe redirect with rails-6.0.0.beta1 --- app/controllers/google_sign_in/authorizations_controller.rb | 1 + 1 file changed, 1 insertion(+) diff --git a/app/controllers/google_sign_in/authorizations_controller.rb b/app/controllers/google_sign_in/authorizations_controller.rb index 08f455d..d6e5eaa 100644 --- a/app/controllers/google_sign_in/authorizations_controller.rb +++ b/app/controllers/google_sign_in/authorizations_controller.rb @@ -3,6 +3,7 @@ class GoogleSignIn::AuthorizationsController < GoogleSignIn::BaseController def create redirect_to login_url(scope: 'openid profile email', state: state), + allow_other_host: true, flash: { proceed_to: params.require(:proceed_to), state: state } end