bugfix/#sonarcloud: Change this code to not perform redirects based on user-controlled data. - step2

This commit is contained in:
Hongwei 2021-02-17 15:06:30 +01:00
parent bdf4aa609e
commit 7a9a44e4f3

View File

@ -283,6 +283,6 @@ class DeleteEntitlementView(LoginRequiredMixin, View):
elif ("/users/myuser/user_id/" in str(redirect_url_from_gui)):
redirect_url = reverse('my-user-detail',kwargs={"user_id":kwargs['user_id']})
else:
redirect_url = redirect_url_from_gui
redirect_url = reverse('users-index')
return HttpResponseRedirect(redirect_url)