mirror of
https://github.com/django/django.git
synced 2025-10-24 06:06:09 +00:00
Prevented reverse() from generating URLs pointing to other hosts.
This is a security fix. Disclosure following shortly.
This commit is contained in:
committed by
Tim Graham
parent
ec71191be0
commit
28e765810d
@@ -75,4 +75,7 @@ with warnings.catch_warnings(record=True):
|
||||
(r'defaults_view2/(?P<arg1>[0-9]+)/', defaults_view, {'arg2': 2}, 'defaults'),
|
||||
|
||||
url('^includes/', include(other_patterns)),
|
||||
|
||||
# Security tests
|
||||
url('(.+)/security/$', empty_view, name='security'),
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user