Quellcode durchsuchen

SEC-1333: Added error message for invalid redirect URL assertion

Luke Taylor vor 16 Jahren
Ursprung
Commit
97a31cae04

+ 2 - 1
web/src/main/java/org/springframework/security/web/authentication/SimpleUrlAuthenticationFailureHandler.java

@@ -66,7 +66,8 @@ public class SimpleUrlAuthenticationFailureHandler implements AuthenticationFail
      * @param defaultFailureUrl the failure URL, for example "/loginFailed.jsp".
      */
     public void setDefaultFailureUrl(String defaultFailureUrl) {
-        Assert.isTrue(UrlUtils.isValidRedirectUrl(defaultFailureUrl));
+        Assert.isTrue(UrlUtils.isValidRedirectUrl(defaultFailureUrl),
+                "'" + defaultFailureUrl + "' is not a valid redirect URL");
         this.defaultFailureUrl = defaultFailureUrl;
     }