From e58dd59c824e39c346763e7bc2a1d58a88cebaa4 Mon Sep 17 00:00:00 2001 From: tkellner Date: Fri, 16 Dec 2011 10:16:38 +0000 Subject: ignore whitespace redirectURLs git-svn-id: https://joinup.ec.europa.eu/svn/mocca/trunk@1001 8a26b1a7-26f0-462f-b9ef-d0e30c41f5a4 --- .../src/main/java/at/gv/egiz/bku/binding/HTTPBindingProcessorImpl.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bkucommon/src/main/java/at/gv/egiz/bku/binding/HTTPBindingProcessorImpl.java b/bkucommon/src/main/java/at/gv/egiz/bku/binding/HTTPBindingProcessorImpl.java index 18e38752..45e966d9 100644 --- a/bkucommon/src/main/java/at/gv/egiz/bku/binding/HTTPBindingProcessorImpl.java +++ b/bkucommon/src/main/java/at/gv/egiz/bku/binding/HTTPBindingProcessorImpl.java @@ -610,7 +610,7 @@ public class HTTPBindingProcessorImpl extends AbstractBindingProcessor implement public String getRedirectURL() { String redirectURL = getFormParameterAsString(FixedFormParameters.REDIRECTURL); log.debug("Evaluating redirectURL: " + redirectURL); - if (redirectURL == null || redirectURL.isEmpty() || redirectURL.contains("\r") || redirectURL.contains("\n") || + if (redirectURL == null || redirectURL.trim().isEmpty() || redirectURL.contains("\r") || redirectURL.contains("\n") || redirectURL.contains("<") || redirectURL.toLowerCase().contains("javascript:")) return null; return redirectURL; -- cgit v1.2.3