Skip to main content

safe_next

Function safe_next 

Source
pub fn safe_next(next: Option<&str>) -> &str
Expand description

Only same-site relative paths are allowed as a post-login destination, so ?next= can’t be used to bounce a user to another site. Browsers drop tabs and newlines from a redirect address (/\t/evil.com becomes //evil.com), so any whitespace or control character rejects the value outright; it also keeps the Location header valid.