BackUrl::sanitizeForLinks 增强:拒绝协议相对 URL(//evil.com)并补单测
This commit is contained in:
@@ -22,6 +22,11 @@ class BackUrl
|
||||
return '';
|
||||
}
|
||||
|
||||
// 拒绝协议相对 URL(例如 //evil.com),避免 open redirect
|
||||
if (str_starts_with($incomingBack, '//')) {
|
||||
return '';
|
||||
}
|
||||
|
||||
if (preg_match('/["\'<>]/', $incomingBack)) {
|
||||
return '';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user