1
0
mirror of https://github.com/django/django.git synced 2025-10-24 06:06:09 +00:00

Prevented reverse() from generating URLs pointing to other hosts.

This is a security fix. Disclosure following shortly.
This commit is contained in:
Florian Apolloner
2014-07-17 21:59:28 +02:00
committed by Tim Graham
parent ec71191be0
commit 28e765810d
6 changed files with 50 additions and 1 deletions

View File

@@ -75,4 +75,7 @@ with warnings.catch_warnings(record=True):
(r'defaults_view2/(?P<arg1>[0-9]+)/', defaults_view, {'arg2': 2}, 'defaults'),
url('^includes/', include(other_patterns)),
# Security tests
url('(.+)/security/$', empty_view, name='security'),
)