Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update webserver.js - allow saml relaystate in POST request #6685

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

nmmclwhitehead
Copy link
Contributor

added relaystate and regex check to prevent redirecting to a page outside of the configured server. also checks for the allowed query params

ref #6272

added check for relaystate saml and regex check
@si458
Copy link
Collaborator

si458 commented Jan 11, 2025

the is lots more RegExp to check, below is the ones ive found you missed
hint look for urlargs in the handlebars files

lang
sitestyle
key
locale
user
pass
gotomesh
gotouser
gotougrp
debug
filter
webrtc
hide

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants