From d5909c9248fbf7ad986d406845488d6b5f2b5bdf Mon Sep 17 00:00:00 2001 From: Axel Guckelsberger Date: Mon, 20 Sep 2021 15:38:14 +0200 Subject: [PATCH] consider local uri for redirect handling --- src/system/UsersModule/Controller/AccessController.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/system/UsersModule/Controller/AccessController.php b/src/system/UsersModule/Controller/AccessController.php index 22856a3a5e..cd30e7b350 100644 --- a/src/system/UsersModule/Controller/AccessController.php +++ b/src/system/UsersModule/Controller/AccessController.php @@ -221,6 +221,10 @@ private function sanitizeReturnUrl(Request $request, $returnUrl = null) return $returnUrl; } + if (false !== mb_strpos($returnUrl, $request->getUriForPath(''))) { + return $returnUrl; + } + if ('/' !== mb_substr($returnUrl, 0, 1)) { $returnUrl = '/' . $returnUrl; }