mirror of
https://github.com/OrchardCMS/Orchard.git
synced 2025-10-15 19:54:57 +08:00
Fixing possibility of open redirection attack on post-registration screens
Fixing the fix of #2295.
This commit is contained in:
@@ -1,4 +1,6 @@
|
||||
@model dynamic
|
||||
<h1>@Html.TitleForPage(T("Challenge Email Sent").ToString()) </h1>
|
||||
<p>@T("An email has been sent to you. Please click on the link it contains in order to have access on this site.") </p>
|
||||
<p>@Html.Link(T("Go back to where you were"), Url.Content(Request.QueryString["ReturnUrl"]))</p>
|
||||
@if (Url.IsLocalUrl(Request.QueryString["ReturnUrl"])) {
|
||||
<p>@Html.Link(T("Go back to where you were"), Url.Content(Request.QueryString["ReturnUrl"]))</p>
|
||||
}
|
@@ -1,4 +1,6 @@
|
||||
@model dynamic
|
||||
<h1>@Html.TitleForPage(T("User Registration Pending").ToString()) </h1>
|
||||
<p>@T("Your user account has been created but has to be approved before it can be used.")</p>
|
||||
<p>@Html.Link(T("Go back to where you were"), Url.Content(Request.QueryString["ReturnUrl"]))</p>
|
||||
@if (Url.IsLocalUrl(Request.QueryString["ReturnUrl"])) {
|
||||
<p>@Html.Link(T("Go back to where you were"), Url.Content(Request.QueryString["ReturnUrl"]))</p>
|
||||
}
|
Reference in New Issue
Block a user