[security feature] Require explicit opt-in for allowing redirect http->https

Đang mở
#1,879 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
45/100
Loại issue
Tính năng
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Sôi nổi
Công nghệ
python
Lĩnh vực
api, security

Hướng nghiên cứu

No file or test is identified in the issue. Start by locating the HTTP redirect handling and its existing tests, then determine how the opt-in setting is exposed and verify that the default rejects the redirect while an explicit opt-in preserves it.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement needs investigation

This redirect is a required feature for some enterprise networks, but it's also raised as a security hole by some reviews. We should do an active switch to making it fail by default and allow users to specify the behavior if needed.

Ngôn ngữ chính
Python
Star
716
Fork
446
Merge trung bình
8 ngày 8 giờ
Pull request đã merge (30 ngày)
2

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của tableau/server-client-python

Tất cả issue của tableau/server-client-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.