Repository navigation
fix(indiekit): accept local redirect paths containing -, . and % - #887
Merged
paulrobertlloyd merged 1 commit intoAug 22, 2026
Merged
Conversation
`authorize()` validates the `redirect` query parameter against
`/^\/[\w&/=?]*$/`. That character class has no `.`, `-` or `%`, so ordinary
local paths are refused with "Invalid redirect attempted":
/auth/new-password
/files/upload-photos
/posts/2026%2F08
Widening the class alone reopens something the narrow one closed by accident.
`//website.example` starts with a slash and contains only word characters and
a dot, so adding `.` makes it match — and a browser resolves a
protocol-relative URL as an absolute one, turning the check into an open
redirect.
Allow the characters a path may legitimately contain, and reject a second
leading slash (or a backslash, which browsers normalise to a slash) with a
negative lookahead, so the guard tests the shape of the value rather than
relying on a restrictive character set.
Extends the existing integration test: three cases covering paths that main
rejects today, and four covering off-site forms that must keep returning 403
(//example, ///example, //user@example and /\example).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WGHR7MuyvBaDbAFfAGUxeT
Collaborator
|
Ah, this might explain an error I keep seeing when I log back into my ‘docked’ web app; I sign in and then get an error page possibly due to attempting to redirect back to a page containing a |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #886.
IndieAuth.authorize()validates theredirectquery parameter with/^\/[\w&/=?]*$/. That class contains no.,-or%, so ordinary local paths are rejected with "Invalid redirect attempted":/auth/new-password/files/upload-photos/posts/2026%2F08Why not just add the characters
The narrow class is also what stops a protocol-relative URL.
//website.examplestarts with a slash and contains only word characters and a dot, so adding.alone makes it match, and a browser resolves that ashttps://website.example— an open redirect.So this keeps the guard on the shape of the value rather than on the character set:
The negative lookahead rejects a second leading slash, and a backslash, since browsers normalise
/\to//.Tests
Extends
403-session-auth-invalid-redirect.js:mainrejects today and should not — these fail without the change and pass with it;//external.example,///external.example,//user@external.exampleand/\external.example. These pass onmaintoo; they are there so a later widening of the class cannot quietly reopen the redirect.node --testinpackages/indiekit: 105 tests, 105 passing; 98/98 onmainbefore this change.