Skip to content

fix: prevent token leak via URL userinfo host confusion#2000

Merged
gavinbarron merged 2 commits into
devfrom
mmainer/sec-user-info-host-confusion
Jun 16, 2026
Merged

fix: prevent token leak via URL userinfo host confusion#2000
gavinbarron merged 2 commits into
devfrom
mmainer/sec-user-info-host-confusion

fix: update URL parsing to reject userinfo and prevent host-confusion…

1be0c0a
Select commit
Loading
Failed to load commit list.