Make WordPress Core


Ignore:
Timestamp:
03/24/2026 02:18:45 AM (5 months ago)
Author:
pento
Message:

Application Passwords: Allow HTTP loopback redirect URLs

This change allows HTTP redirect URLs for loopback addresses (127.0.0.1, [::1]) in wp_is_authorize_application_redirect_url_valid(), regardless of environment type. This aligns the application password implementation with RFC 8252 7.3.

It's worth noting that section 8.3 of the RFC recommends against allowing localhost as a loopback redirect, since it may be susceptible to firewall interception and DNS resolution poisoning.

Props aquarius, pento.
Fixes #57809.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/tests/phpunit/tests/admin/Admin_Includes_User_WpIsAuthorizeApplicationPasswordRequestValid_Test.php

    r61407 r62096  
    8282                                'env'                 => $environment_type,
    8383                        );
     84
     85                        $datasets[ $environment_type . ' and a "http" loopback "success_url"' ] = array(
     86                                'request'             => array( 'success_url' => 'http://127.0.0.1:8080/callback' ),
     87                                'expected_error_code' => '',
     88                                'env'                 => $environment_type,
     89                        );
     90
     91                        $datasets[ $environment_type . ' and a "http" loopback "reject_url"' ] = array(
     92                                'request'             => array( 'reject_url' => 'http://127.0.0.1/callback' ),
     93                                'expected_error_code' => '',
     94                                'env'                 => $environment_type,
     95                        );
    8496                }
    8597
Note: See TracChangeset for help on using the changeset viewer.