Skip to content

Validate intended login redirects - #378

Open
bjarn wants to merge 2 commits into
ploi:mainfrom
bjarn:codex/validate-login-intended-url
Open

bjarn wants to merge 2 commits into
ploi:mainfrom
bjarn:codex/validate-login-intended-url

Conversation

@bjarn

@bjarn bjarn commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Accept local paths and same-origin HTTP or HTTPS URLs only.
  • Reject external, protocol-relative, malformed, and non-HTTP destinations.
  • Clear an unsafe intended URL from the session.
  • Add redirect regression tests.

Security impact

A crafted login link could redirect a user to an external site after authentication.

Tests

  • php artisan test --compact tests/Feature/Auth/LoginTest.php

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant