Address commit security review: the same-origin branch of safeUrl accepted //host and /\host, which browsers normalize to an external host (open redirect). Allow only true same-origin paths. |
||
|---|---|---|
| .. | ||
| assets | ||
| pitch-assets | ||
| app.js | ||
| evidence-guidance.js | ||
| index.html | ||
| operator-labels.js | ||
| operator-search.js | ||
| pitch.css | ||
| pitch.html | ||
| pitch.js | ||
| styles.css | ||
| submission-import.js | ||