]> git.evergreen-ils.org Git - Evergreen.git/commit
LP#1314827: On login, don't allow referer-based redirect to external site
authorJeff Davis <jdavis@sitka.bclibraries.ca>
Fri, 16 May 2014 22:14:43 +0000 (15:14 -0700)
committerBen Shum <bshum@biblio.org>
Fri, 3 Oct 2014 06:20:41 +0000 (02:20 -0400)
commitc6d474d27ead75a1365e44dea4144cd701c28e02
tree9f424e9d16466de4ae81627639604b8b184a3fe4
parent81dd489c33e70bfe5b04f1f5cfaab9f4de5e6e32
LP#1314827: On login, don't allow referer-based redirect to external site

On /eg/opac/login, if no redirect_to param is provided, the TPAC will
attempt to use the referer (if any) as the redirect destination. This
leads to undesirable behavior if the referring URL is from an external
site.

Signed-off-by: Jeff Davis <jdavis@sitka.bclibraries.ca>
Signed-off-by: Ben Shum <bshum@biblio.org>
Open-ILS/src/templates/opac/parts/login/form.tt2