mirror of
https://github.com/django/django.git
synced 2025-08-02 18:13:02 +00:00
Prevented reverse() from generating URLs pointing to other hosts.
This is a security fix. Disclosure following shortly.
This commit is contained in:
parent
ec71191be0
commit
28e765810d
6 changed files with 50 additions and 1 deletions
|
@ -152,6 +152,9 @@ test_data = (
|
|||
('defaults', '/defaults_view2/3/', [], {'arg1': 3, 'arg2': 2}),
|
||||
('defaults', NoReverseMatch, [], {'arg1': 3, 'arg2': 3}),
|
||||
('defaults', NoReverseMatch, [], {'arg2': 1}),
|
||||
|
||||
# Security tests
|
||||
('security', '/%2Fexample.com/security/', ['/example.com'], {}),
|
||||
)
|
||||
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue