wagtail icon indicating copy to clipboard operation
wagtail copied to clipboard

SwapController - Ensure untrusted data sources are logged correctly

Open lb- opened this issue 2 years ago • 1 comments

Avoids the rare case of requestUrl being used to log out an object in an unhanded way.

See https://developer.mozilla.org/en-US/docs/Web/API/console#s

Fixes #11212

lb- avatar Nov 09 '23 20:11 lb-

Manage this branch in Squash

Test this branch here: https://lb-fix11212-swap-controller-er-r9q3l.squash.io

squash-labs[bot] avatar Nov 09 '23 20:11 squash-labs[bot]

@laymonage - any chance for a review on this?

Super small change and a low risk but flagged with our security reporting (see issue).

I could just merge but wanted someone else to just look to check it's OK.

lb- avatar Mar 23 '24 05:03 lb-

Thanks.

lb- avatar Mar 23 '24 08:03 lb-