Skip to content
Discussion options

You must be logged in to vote

Hi @cmellongoempyrean, thanks for creating a discussion. You're largely right in your understanding.

What we did deliberately was apply confinement uniformly to most templates, rather than tailoring it field by field. We made the judgment call to over-restrict now and relax later. Given that we provide a way to fully preserve existing behavior, and that this also resolved issues reported here, we deemed it was worth it.

For path- and routing-style fields, confinement is a genuine defense against traversal and redirection; for others it's a weaker guarantee, hence we don't consider the current iteration final. The most useful way to move that forward is the following: if you think confinem…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@cmellongoempyrean
Comment options

@pront
Comment options

Answer selected by cmellongoempyrean
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
domain: security Anything related to security
2 participants