Skip to content

fix(security): validate redirect destination to prevent open redirects (#518) - #527

Open
lmduy2612 wants to merge 1 commit into
ChainLearnOfficial:mainfrom
lmduy2612:fix/middleware-open-redirect-518
Open

lmduy2612 wants to merge 1 commit into
ChainLearnOfficial:mainfrom
lmduy2612:fix/middleware-open-redirect-518

Conversation

@lmduy2612

Copy link
Copy Markdown

Summary

Closes #518.

Implements strict validation on the redirect query parameter in src/middleware.ts when bouncing authenticated users from authentication routes, preventing open redirect and phishing vectors via crafted //evil.com or external scheme URLs.

Changes Made

  • Added getSafeRedirect helper in src/middleware.ts:
    • Ensures redirect begins with a single /.
    • Rejects protocol-relative URLs starting with //.
    • Rejects URLs containing backslashes (\) or protocol schemes (e.g., http:, https:, javascript:, data:).
    • Safely falls back to /dashboard when validation fails or parameter is empty.
  • Added comprehensive unit tests in src/middleware.test.ts verifying rejection of malicious URLs and acceptance of legitimate internal application routes.

Acceptance Criteria

  • Validate that redirect starts with /
  • Reject values containing // (protocol-relative URLs)
  • Reject values with protocol schemes (http:, javascript:, etc.)
  • Default to /dashboard if validation fails

@netlify

netlify Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

❌ Deploy Preview for chainlearn failed.

Name Link
🔨 Latest commit f9068e2
🔍 Latest deploy log https://app.netlify.com/projects/chainlearn/deploys/6abf71061cafd50008e576c6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Middleware redirect parameter is not validated — open redirect vulnerability

1 participant