express-openid-connect
Advanced tools
Comparing version 2.7.1 to 2.7.2
@@ -190,3 +190,4 @@ const cb = require('cb'); | ||
} else if (req.method === 'GET' && req.originalUrl) { | ||
returnTo = req.originalUrl; | ||
// Collapse any leading slashes to a single slash to prevent Open Redirects | ||
returnTo = req.originalUrl.replace(/^\/+/, '/'); | ||
debug('req.oidc.login() without returnTo, using: %s', returnTo); | ||
@@ -193,0 +194,0 @@ } |
{ | ||
"name": "express-openid-connect", | ||
"version": "2.7.1", | ||
"version": "2.7.2", | ||
"description": "Express middleware to protect web applications using OpenID Connect.", | ||
@@ -5,0 +5,0 @@ "homepage": "https://github.com/auth0/express-openid-connect", |
83383
2343