mirror of
https://github.com/bitwarden/server.git
synced 2025-07-01 08:02:49 -05:00
[PM-3571] Address HTML injection in passwordless login emails (#3623)
* [PM-3571] Update HandlebarsMailService for Passwordless login email URL, using AbsoluteUri which has html encoding * [PM-3571] Switched from AbsoluteUri to OriginalString --------- Co-authored-by: bnagawiecki <107435978+bnagawiecki@users.noreply.github.com>
This commit is contained in:
@ -263,7 +263,7 @@ public class HandlebarsMailService : IMailService
|
||||
});
|
||||
var model = new PasswordlessSignInModel
|
||||
{
|
||||
Url = url.ToString()
|
||||
Url = url.OriginalString
|
||||
};
|
||||
await AddMessageContentAsync(message, "Auth.PasswordlessSignIn", model);
|
||||
message.Category = "PasswordlessSignIn";
|
||||
|
Reference in New Issue
Block a user