RedirectSanitiser instead. Since v6.2.@PublicApi public final class SafeRedirectChecker extends Object implements RedirectSanitiser
| Constructor and Description |
|---|
SafeRedirectChecker(RedirectSanitiser redirectSanitiser)
Deprecated.
|
| Modifier and Type | Method and Description |
|---|---|
boolean |
canRedirectTo(String redirectUri)
Deprecated.
Returns a boolean indicating whether redirecting to the given URI is allowed or not.
|
String |
makeSafeRedirectUrl(String redirectUrl)
Deprecated.
Constructs a safe redirect URL out of user-provided input.
|
@Internal public SafeRedirectChecker(RedirectSanitiser redirectSanitiser)
public boolean canRedirectTo(@Nullable String redirectUri)
redirectUri is an absolute URI and it points to a domain that is not this JIRA instance's
domain, and true otherwise. If the uri is in the form //xxx then it is not allowed as per JRA-27405canRedirectTo in interface RedirectSanitiserredirectUri - a String containing a URI@Nullable public String makeSafeRedirectUrl(@Nullable String redirectUrl)
redirectUrl
does not meet these conditions, this method returns null.
This is used to prevent Open redirect attacks, which facilitate phishing attacks against JIRA users.
makeSafeRedirectUrl in interface RedirectSanitiserredirectUrl - a String containing the redirect URLCopyright © 2002-2023 Atlassian. All Rights Reserved.