Solve a security issue with some modules (not validating URLs we are...
Solve a security issue with some modules (not validating URLs we are redirecting to) by moving the check to the SimpleSAML_Auth_State::loadState() method.
Showing
- lib/SimpleSAML/Auth/ProcessingChain.php 3 additions, 5 deletionslib/SimpleSAML/Auth/ProcessingChain.php
- lib/SimpleSAML/Auth/State.php 2 additions, 2 deletionslib/SimpleSAML/Auth/State.php
- lib/SimpleSAML/IdP/LogoutTraditional.php 0 additions, 6 deletionslib/SimpleSAML/IdP/LogoutTraditional.php
- modules/aselect/www/credentials.php 1 addition, 9 deletionsmodules/aselect/www/credentials.php
- modules/authYubiKey/lib/Auth/Source/YubiKey.php 0 additions, 6 deletionsmodules/authYubiKey/lib/Auth/Source/YubiKey.php
- modules/authfacebook/www/linkback.php 1 addition, 10 deletionsmodules/authfacebook/www/linkback.php
- modules/authlinkedin/www/linkback.php 3 additions, 12 deletionsmodules/authlinkedin/www/linkback.php
- modules/authmyspace/www/linkback.php 2 additions, 11 deletionsmodules/authmyspace/www/linkback.php
- modules/authorize/www/authorize_403.php 1 addition, 10 deletionsmodules/authorize/www/authorize_403.php
- modules/authtwitter/www/linkback.php 1 addition, 9 deletionsmodules/authtwitter/www/linkback.php
- modules/authwindowslive/www/linkback.php 2 additions, 11 deletionsmodules/authwindowslive/www/linkback.php
- modules/cas/www/linkback.php 1 addition, 9 deletionsmodules/cas/www/linkback.php
- modules/cdc/www/resume.php 0 additions, 7 deletionsmodules/cdc/www/resume.php
- modules/consent/www/getconsent.php 0 additions, 7 deletionsmodules/consent/www/getconsent.php
- modules/consent/www/logout.php 1 addition, 9 deletionsmodules/consent/www/logout.php
- modules/consent/www/noconsent.php 0 additions, 7 deletionsmodules/consent/www/noconsent.php
- modules/core/lib/Auth/UserPassBase.php 0 additions, 6 deletionsmodules/core/lib/Auth/UserPassBase.php
- modules/core/lib/Auth/UserPassOrgBase.php 0 additions, 12 deletionsmodules/core/lib/Auth/UserPassOrgBase.php
- modules/core/www/idp/logout-iframe-done.php 1 addition, 9 deletionsmodules/core/www/idp/logout-iframe-done.php
- modules/core/www/idp/logout-iframe.php 1 addition, 8 deletionsmodules/core/www/idp/logout-iframe.php
Please register or sign in to comment