Skip to content
This repository has been archived by the owner on Sep 25, 2024. It is now read-only.

EncodeURI origin app-bridge #1612

Merged
merged 1 commit into from
Aug 26, 2020
Merged

EncodeURI origin app-bridge #1612

merged 1 commit into from
Aug 26, 2020

Conversation

keyfer
Copy link
Contributor

@keyfer keyfer commented Aug 26, 2020

Description

Fixes https://hackerone.shopifycloud.com/reports/966419

Encode the origin parameter to block XSS vulnerabilities

Type of change

  • koa-shopify-auth Patch: Bug (non-breaking change which fixes an issue)

Checklist

  • I have added a changelog entry, prefixed by the type of change noted above (Documentation fix and Test update does not need a changelog as we do not publish new version)

Copy link
Contributor

@ismail-syed ismail-syed left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Based on the context in the PR description this fix makes sense. A small unit test would be ideal, but not going to let that block this XSS issue.

@keyfer keyfer merged commit a05457d into master Aug 26, 2020
@keyfer keyfer deleted the xss-issue-koa-auth branch August 26, 2020 18:27
@keyfer keyfer temporarily deployed to production August 26, 2020 18:40 Inactive
@michenly michenly temporarily deployed to gem August 26, 2020 23:18 Inactive
@ismail-syed ismail-syed deployed to pr-fix-beta-test August 31, 2020 15:04 Active
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants