Title: Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #23 · Pixee-Bot-Java/flow · GitHub
Open Graph Title: Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #23 · Pixee-Bot-Java/flow
X Title: Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #23 · Pixee-Bot-Java/flow
Description: Vaadin Flow is a Java framework binding Vaadin web components to Java. This is part of Vaadin 10+. - Introduced protections against user-controlled internal request forwarding by pixeebot[bot] · Pull Request #23 · Pixee-Bot-Java/flow
Open Graph Description: This change hardens all ServletRequest#getRequestDispatcher(String) calls against attack. There is a built-in HTTP method for sending clients to another resource: the client-side redirect. However,...
X Description: This change hardens all ServletRequest#getRequestDispatcher(String) calls against attack. There is a built-in HTTP method for sending clients to another resource: the client-side redirect. However,...
Opengraph URL: https://github.com/Pixee-Bot-Java/flow/pull/23
X: @github
Domain: patch-diff.githubusercontent.com
| route-pattern | /_view_fragments/voltron/pull_requests/show/:user_id/:repository/:id/pull_request_layout(.:format) |
| route-controller | voltron_pull_requests_fragments |
| route-action | pull_request_layout |
| fetch-nonce | v2:bcf82e6a-4b61-7d0e-50bd-bf2443e99689 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | A3E2:F3DEB:15A207D:1C4F4BF:698FD31D |
| html-safe-nonce | 78dcc21212e3f825c00267e78a0db193df23e4db77cc53a23ae6068cba4fbc22 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBM0UyOkYzREVCOjE1QTIwN0Q6MUM0RjRCRjo2OThGRDMxRCIsInZpc2l0b3JfaWQiOiIzNTkxMzExMzQyMzk5NjQwMzQ5IiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | bf2cdeef1fd36e3f6926ce5596af70d202067109f82fd351ff684feab6a46565 |
| hovercard-subject-tag | pull_request:2343550990 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/voltron/pull_requests/show/Pixee-Bot-Java/flow/23/pull_request_layout |
| twitter:image | https://opengraph.githubassets.com/a9dd2ab18dc29d3d28e57c1163cb7dab96a2ccf3936416565aa8d005451dd22b/Pixee-Bot-Java/flow/pull/23 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/a9dd2ab18dc29d3d28e57c1163cb7dab96a2ccf3936416565aa8d005451dd22b/Pixee-Bot-Java/flow/pull/23 |
| og:image:alt | This change hardens all ServletRequest#getRequestDispatcher(String) calls against attack. There is a built-in HTTP method for sending clients to another resource: the client-side redirect. However,... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | pixeebot[bot] |
| hostname | github.com |
| expected-hostname | github.com |
| None | 42c603b9d642c4a9065a51770f75e5e27132fef0e858607f5c9cb7e422831a7b |
| turbo-cache-control | no-cache |
| go-import | github.com/Pixee-Bot-Java/flow git https://github.com/Pixee-Bot-Java/flow.git |
| octolytics-dimension-user_id | 143516492 |
| octolytics-dimension-user_login | Pixee-Bot-Java |
| octolytics-dimension-repository_id | 795756272 |
| octolytics-dimension-repository_nwo | Pixee-Bot-Java/flow |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | true |
| octolytics-dimension-repository_parent_id | 34809191 |
| octolytics-dimension-repository_parent_nwo | vaadin/flow |
| octolytics-dimension-repository_network_root_id | 34809191 |
| octolytics-dimension-repository_network_root_nwo | vaadin/flow |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | d320682233dfd4d28c0b30554a564c2fcd229032 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width