Skip to content

Commit 21fb973

Browse files
Merge pull request #20 from Shopify/changes-to-release
Harden App Home Redirect URL handling.
2 parents 04ceeb1 + cf0302a commit 21fb973

3 files changed

Lines changed: 11 additions & 2 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
66
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
77

8+
## [1.0.2]
9+
10+
- Harden App Home Redirect URL handling.
11+
812
## [1.0.1]
913

1014
- Redact log response for exchange and refresh methods.

‎shopify_app/_version.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,4 +2,4 @@
22

33
from __future__ import annotations
44

5-
__version__ = "1.0.1"
5+
__version__ = "1.0.2"

‎shopify_app/helpers/app_home_redirect.py‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ def app_home_redirect(
7070
shop=shop,
7171
log=LogWithReq(
7272
code="invalid_redirect_url",
73-
detail=f"Redirect URL must be a relative path starting with '/'. Received {redirect_url}. Respond 400 Bad Request using the provided response.",
73+
detail="Redirect URL was not a safe root-relative path. Respond 400 Bad Request using the provided response.",
7474
req=req,
7575
),
7676
response=Res(status=400, body="Bad Request", headers={}),
@@ -171,6 +171,11 @@ def _is_valid_relative_url(redirect_url: str) -> bool:
171171
if redirect_url.startswith("//"):
172172
return False
173173

174+
# Browsers remove tabs, line feeds, and carriage returns during URL
175+
# preprocessing, which can turn an accepted URL into a protocol-relative URL
176+
if any(control in redirect_url for control in ("\t", "\n", "\r")):
177+
return False
178+
174179
# Must not be backslash-prefixed (/\evil.com) — browsers normalize \ to /
175180
# per the WHATWG URL Standard, turning it into a protocol-relative URL
176181
if len(redirect_url) > 1 and redirect_url[1] == "\\":

0 commit comments

Comments
 (0)