Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve onsiteURL regex to prevent jumping out the origin domain #57

Merged
merged 2 commits into from
Nov 13, 2020

Conversation

spassarop
Copy link
Collaborator

- It actually prevents jumping out the origin domain.
- Updated on every policy.
@davewichers
Copy link
Collaborator

davewichers commented Nov 13, 2020

Looks good. Merging now and I'll test it after the merge to make sure. Your new test fails when I revert the policy change, and passes with the change. So looks good to me.

@nahsra - any thoughts on this change? Look good to you?

@davewichers davewichers merged commit e59963e into nahsra:1.5.11 Nov 13, 2020
@spassarop spassarop deleted the fix-onsiteurl branch January 25, 2021 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants