CodeForAfrica / sourceAFRICA

sourceAFRICA is the continent's largest repository of documentary evidence and other "actionable documents" from investigative journalists and civic watchdogs. Forked from DocumentCloud.org, and built on the Ruby on Rails framework, the project is accessible here: https://sourceafrica.net/
https://sourceafrica.net
Other
11 stars 9 forks source link

Limit redirects to relative URLs only #81

Open kilemensi opened 1 year ago

kilemensi commented 1 year ago

Description

This PR limits the redirect handler to relative paths only due to security issues.