CakeDC / users

Users Plugin for CakePHP
https://www.cakedc.com
Other
521 stars 296 forks source link

Feature/block redirect to host not allowed #955

Closed steinkel closed 3 years ago

steinkel commented 3 years ago

The patch provided covers the case when:

^ In this case, a redirect was possible to an external domain

AFTER the patch, the redirect only happens if the domain is included in Users.AllowedRedirectHosts