• Stan Hu's avatar
    Escape username and password in UrlSanitizer#full_url · a2a21c5e
    Stan Hu authored
    If a user uses a password with certain characters (e.g. /, #, +, etc.)
    UrlSanitizer#full_url will generate an invalid URL that cannot be
    parsed properly by Addressable::URI. If used with UrlBlocker, this
    will be flagged as an invalid URI.
    a2a21c5e
url_sanitizer.rb 2.44 KB