From: Tom Hughes Date: Tue, 23 Nov 2021 17:19:55 +0000 (+0000) Subject: Validate any origin passed the auth failure callback X-Git-Tag: live~1430 X-Git-Url: https://git.openstreetmap.org/rails.git/commitdiff_plain/abbd5a30d41945a41ed5c6c2012793e176f8c28a Validate any origin passed the auth failure callback Fixes #3375 --- diff --git a/app/controllers/users_controller.rb b/app/controllers/users_controller.rb index b90fbea11..23263ebba 100644 --- a/app/controllers/users_controller.rb +++ b/app/controllers/users_controller.rb @@ -332,7 +332,10 @@ class UsersController < ApplicationController # omniauth failure callback def auth_failure flash[:error] = t(params[:message], :scope => "users.auth_failure", :default => t("users.auth_failure.unknown_error")) - redirect_to params[:origin] || login_url + + origin = safe_referer(params[:origin]) if params[:origin] + + redirect_to origin || login_url end private diff --git a/test/controllers/users_controller_test.rb b/test/controllers/users_controller_test.rb index 23c67794a..44b5471ac 100644 --- a/test/controllers/users_controller_test.rb +++ b/test/controllers/users_controller_test.rb @@ -896,4 +896,18 @@ class UsersControllerTest < ActionDispatch::IntegrationTest assert_equal "deleted", normal_user.reload.status assert_equal "deleted", confirmed_user.reload.status end + + def test_auth_failure_callback + get auth_failure_path + assert_response :redirect + assert_redirected_to login_path + + get auth_failure_path, :params => { :origin => "/" } + assert_response :redirect + assert_redirected_to root_path + + get auth_failure_path, :params => { :origin => "http://www.google.com" } + assert_response :redirect + assert_redirected_to login_path + end end