angler-fishThe Vulnerability History Project

Fixed #11457: tightened the security check for "next" redirects after logins.

      The new behavior still disallows redirects to off-site URLs, but now allows
redirects of the form `/some/other/view?foo=http://...`.

Thanks to brutasse.

git-svn-id: http://code.djangoproject.com/svn/django/trunk@12635 bcc190cf-cafb-0310-a4f2-bffc1f526a37
    
commit 6e748b5db4ea6db78ce389f474c2fb78ee3976ed
+1 -42
+4 -23
expand_less