📝 `RedirectTo` accepts protocol-relative URLs (#1326)
django-modern-rest/dmr/response.py
Lines 164 to 168 in a2d44b1
This might be a bug in Django as well.
>>> from urllib.parse import urlsplit
>>> urlsplit('//evil.example/x').scheme
''
So, the
scheme check is skipped.Django has https://github.com/django/django/blob/73cc09f14f13fedddc14d6ba5b287cb33c24e4a4/django/utils/http.py#L274 for this case.
And this is how it is used: https://github.com/django/django/blob/73cc09f14f13fedddc14d6ba5b287cb33c24e4a4/django/contrib/auth/views.py#L43-L59
We need to add docs about
RedirectTo usage. So, developers will know that redirects to users' paths are not always safe.(please, do not take this issue before the 1st of September)
#documentation #good_first_issue #help_wanted #security #opensource_september #django_modern_rest
sent via relator