Skip to content

Conversation

kyoshidajp
Copy link

I think that Authorization header should not be forwarded to cross-site when redirecting.

The administrator of the site that the victim accesses by the redirect can get the secret information.

(Excuse me, I'm not sure about writing redirect test by Test::Unit.)

@kyoshidajp kyoshidajp force-pushed the clear-auth-header-when-redirect branch from 9cb0c88 to 1e8a307 Compare February 19, 2019 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant