mirror of
https://github.com/keycloak/keycloak
synced 2025-05-16 23:30:01 +00:00
Closes https://github.com/keycloak/security/issues/22 Co-authored-by: Stian Thorgersen <stianst@gmail.com> Signed-off-by: Peter Skopek <pskopek@redhat.com>
4 lines
392 B
Plaintext
4 lines
392 B
Plaintext
= Changes in validating schemes for valid redirect URIs
|
|
|
|
If an application client is using non http(s) custom schemes, from now on the validation requires that a valid redirect pattern explicitly allows that scheme. Example patterns for allowing `custom` scheme are `custom:/test`, `custom:/test/\*` or `custom:*`. For security reasons a general pattern like `*` does not cover them anymore.
|