Skip to content

Fix HTML injection in SAML POST login#1037

Merged
blizzz merged 3 commits intomasterfrom
fix/login-post-escape
Jan 29, 2026
Merged

Fix HTML injection in SAML POST login#1037
blizzz merged 3 commits intomasterfrom
fix/login-post-escape

Conversation

@hweihwang
Copy link
Contributor

@hweihwang hweihwang commented Jan 28, 2026

Summary

  • escape SAML POST template values with p()
  • add unit coverage to ensure escaping

Signed-off-by: Hoang Pham <hoangmaths96@gmail.com>
@hweihwang hweihwang assigned hweihwang and unassigned hweihwang Jan 28, 2026
Signed-off-by: Hoang Pham <hoangmaths96@gmail.com>
Signed-off-by: Hoang Pham <hoangmaths96@gmail.com>
@hweihwang hweihwang requested a review from blizzz January 28, 2026 11:46
@blizzz blizzz merged commit 05556e9 into master Jan 29, 2026
85 of 88 checks passed
@blizzz blizzz deleted the fix/login-post-escape branch January 29, 2026 11:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants