This repository has been archived on 2023-03-18. You can view files and clone it, but cannot push or open issues or pull requests.
osr-discourse-src/spec/requests
Sam Saffron 40ac895ef7 SECURITY: properly validate return URL for SSO
Previously carefully crafted URLs could redirect off site
2019-03-25 09:02:42 +11:00
..
admin
about_controller_spec.rb
application_controller_spec.rb
badges_controller_spec.rb
categories_controller_spec.rb
category_hashtags_controller_spec.rb
clicks_controller_spec.rb
composer_controller_spec.rb
composer_messages_controller_spec.rb
csp_reports_controller_spec.rb
directory_items_controller_spec.rb
draft_controller_spec.rb
drafts_controller_spec.rb
email_controller_spec.rb
embed_controller_spec.rb
exceptions_controller_spec.rb
export_csv_controller_spec.rb
extra_locales_controller_spec.rb
finish_installation_controller_spec.rb
groups_controller_spec.rb
inline_onebox_controller_spec.rb
invites_controller_spec.rb
list_controller_spec.rb
metadata_controller_spec.rb
notifications_controller_spec.rb
offline_controller_spec.rb
omniauth_callbacks_controller_spec.rb
onebox_controller_spec.rb
permalinks_controller_spec.rb
post_action_users_controller_spec.rb
post_actions_controller_spec.rb
posts_controller_spec.rb
push_notification_controller_spec.rb
queued_posts_controller_spec.rb
robots_txt_controller_spec.rb
safe_mode_controller_spec.rb
search_controller_spec.rb
session_controller_spec.rb SECURITY: properly validate return URL for SSO 2019-03-25 09:02:42 +11:00
similar_topics_controller_spec.rb
site_controller_spec.rb
static_controller_spec.rb
steps_controller_spec.rb
stylesheets_controller_spec.rb
svg_sprite_controller_spec.rb
tag_groups_controller_spec.rb
tags_controller_spec.rb
theme_javascripts_controller_spec.rb
topics_controller_spec.rb
uploads_controller_spec.rb
user_actions_controller_spec.rb
user_api_keys_controller_spec.rb
user_avatars_controller_spec.rb
user_badges_controller_spec.rb
users_controller_spec.rb
users_email_controller_spec.rb
webhooks_controller_spec.rb
wizard_controller_spec.rb