Skip to content

Commit b02658f

Browse files
authored
Remove usage of 'next' url cookie (#2621)
1 parent bddaba6 commit b02658f

File tree

2 files changed

+2
-6
lines changed

2 files changed

+2
-6
lines changed

authentication/views.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ def get_redirect_url(request, param_names):
2626
str: Redirect URL
2727
"""
2828
for param_name in param_names:
29-
next_url = request.GET.get(param_name) or request.COOKIES.get(param_name)
29+
next_url = request.GET.get(param_name)
3030
if next_url and url_has_allowed_host_and_scheme(
3131
next_url, allowed_hosts=settings.ALLOWED_REDIRECT_HOSTS
3232
):

main/middleware/apisix_user.py

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -153,7 +153,6 @@ def process_request(self, request):
153153
if settings.DISABLE_APISIX_USER_MIDDLEWARE:
154154
return super().process_request(request)
155155
apisix_user = None
156-
next_param = request.GET.get("next", None) if request.GET else None
157156
if request.META.get(self.header):
158157
new_header = decode_apisix_headers(
159158
request, self.header, model=settings.AUTH_USER_MODEL
@@ -192,7 +191,4 @@ def process_request(self, request):
192191
log.debug("Forcing user logout because no APISIX user was found")
193192
logout(request)
194193

195-
response = self.get_response(request)
196-
if next_param:
197-
response.set_cookie("next", next_param, max_age=30, secure=False)
198-
return response
194+
return self.get_response(request)

0 commit comments

Comments
 (0)