fix(frontend): sanitize redirect targets to prevent XSS/open redirect

Sanitize and validate redirect targets from callbackUrl parameter and sessionStorage in login, registration, and OAuth callback flows.
Introduced safeRedirectTarget helper which rejects protocol-relative URLs, non-relative schemes, control characters, backslashes, and encoding bypasses.
This commit is contained in:
ryan
2026-06-13 09:51:30 +08:00
parent 50d21b431b
commit f48426dbf8
4 changed files with 61 additions and 4 deletions
+3 -1
View File
@@ -11,6 +11,7 @@ import {Check} from "lucide-react"
import services from "@/lib/services"
import {useAuth} from "@/components/providers/auth-provider"
import {safeRedirectTarget} from "@/lib/utils"
/**
@@ -48,9 +49,10 @@ export function LoginPage() {
sessionStorage.removeItem('redirect_after_login')
}
return target
return safeRedirectTarget(target)
}, [searchParams])
/* 登录页兜底:已登录用户直接跳转 */
useEffect(() => {
const state = searchParams.get('state')