]> git.evergreen-ils.org Git - Evergreen.git/commit
LP#1314827: On login, don't allow referer-based redirect to external site
authorJeff Davis <jdavis@sitka.bclibraries.ca>
Fri, 16 May 2014 22:14:43 +0000 (15:14 -0700)
committerBen Shum <bshum@biblio.org>
Fri, 3 Oct 2014 06:19:22 +0000 (02:19 -0400)
commitfcf4628204e757692a92595c20a04c99c83e6329
treef352bc9f9c09e2af35f1fd52111bf268cb23fc72
parent4ab439f604b4b5df1c3252665be06e731220b1f4
LP#1314827: On login, don't allow referer-based redirect to external site

On /eg/opac/login, if no redirect_to param is provided, the TPAC will
attempt to use the referer (if any) as the redirect destination. This
leads to undesirable behavior if the referring URL is from an external
site.

Signed-off-by: Jeff Davis <jdavis@sitka.bclibraries.ca>
Signed-off-by: Ben Shum <bshum@biblio.org>
Open-ILS/src/templates/opac/parts/login/form.tt2