Previously external domains were allowed in the client-side redirects, but not the server-side redirects. Now the behavior is to only allow local origins. |
||
|---|---|---|
| .. | ||
| omniauth_callbacks_controller.rb | ||
Previously external domains were allowed in the client-side redirects, but not the server-side redirects. Now the behavior is to only allow local origins. |
||
|---|---|---|
| .. | ||
| omniauth_callbacks_controller.rb | ||