fix(auth): Reject static asset paths as post-login redirects - #123095
Open
nora-shap wants to merge 2 commits into
Open
fix(auth): Reject static asset paths as post-login redirects#123095nora-shap wants to merge 2 commits into
nora-shap wants to merge 2 commits into
Conversation
Session `_next` can be poisoned by unauthenticated requests for assets like service-worker source maps. Honor valid app destinations; fall back to the normal login default when the path is a static asset. Co-Authored-By: Nora Shapiro <nora.shapiro@sentry.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
During my testing of the new user SSO flow (in prod), I was able to repeatedly trigger a bug where we try to redirect you to a service worker source map after you successfully login for the first time.
Unauthenticated requests for static assets can be stored as session
_next. After login, we send users to those paths, which the SPA treated as org/project routes, leaving the new user on theThe project you were looking for was not foundpage.To prevent any other new users from experiencing this erroneous redirect, extend the checks in
is_valid_redirect()