Browse Source

Make sure "next" url is safe

Peter Justin 4 years ago
parent
commit
918f4eab75
1 changed files with 1 additions and 1 deletions
  1. 1 1
      flaskbb/utils/helpers.py

+ 1 - 1
flaskbb/utils/helpers.py

@@ -95,7 +95,7 @@ def redirect_or_next(endpoint, use_referrer=True):
     :param endpoint: The fallback endpoint.
     """
     return redirect(
-        request.args.get("next")
+        redirect_url(request.args.get("next"), use_referrer)
         or redirect_url(endpoint, use_referrer)
     )