fix: sanitize URLs used for OAuth auth flow (via #5190)
* fix: sanitize URLs used for OAuth auth flow * embetter test case * fix linter issue
This commit is contained in:
5
test/e2e-cypress/static/documents/xss/oauth2.yaml
Normal file
5
test/e2e-cypress/static/documents/xss/oauth2.yaml
Normal file
@@ -0,0 +1,5 @@
|
||||
swagger: '2.0'
|
||||
securityDefinitions:
|
||||
a:
|
||||
type: oauth2
|
||||
authorizationUrl: javascript:alert(document.domain)//
|
||||
Reference in New Issue
Block a user