Skip to content

Enforce that redirect URL should be on the same origin as the app #235

@jonkoops

Description

@jonkoops

Currently, it is possible for Keycloak JS to be initialized with a redirect URL that is not on the same origin as the application it is being initialized on. This is often used as a redirect mechanism, but can cause unexpected issues, and should be prevented.

See #230

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/taskA task with no user impact

    Type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions