Skip to content

fix(server): only redirect form posts to the Referer - #5866

Open
SulimanAbdulrazzaq wants to merge 1 commit into
DioxusLabs:mainfrom
SulimanAbdulrazzaq:fix/serverfn-get-referer-redirect
Open

SulimanAbdulrazzaq wants to merge 1 commit into
DioxusLabs:mainfrom
SulimanAbdulrazzaq:fix/serverfn-get-referer-redirect

Conversation

@SulimanAbdulrazzaq

Copy link
Copy Markdown

Fixes #5445. Follow-up to #5428 / #5429.

Problem

ServerFunction::make_handler turns a successful response into 302 Found with Location: <Referer> whenever the request accepts text/html and carries a Referer. The comment says this is the Post/Redirect/Get step for a plain form post, but nothing checks the method, so it also fires on browser GET navigations:

Fix

Apply the redirect only to POST requests. HTML forms can only submit GET or POST, so this keeps the form-post behavior and lets a GET navigation receive the handler's response.

Tests

Two unit tests in packages/fullstack-server/src/serverfn.rs send a browser-style request (Accept: text/html,..., Referer: http://localhost:8080/page) through make_handler:

  • get_navigation_returns_the_response_instead_of_redirecting_to_referer: a GET gets 200 and the handler's body. Before this change it gets 302 to the Referer.
  • plain_form_post_still_redirects_to_referer: a POST still gets 302 with Location set to the Referer.

cargo test -p dioxus-server --lib --bins --tests --examples, cargo clippy -p dioxus-server --tests -- -D warnings and rustfmt --check on the touched file pass.

A server function answered every successful request that accepted
text/html and carried a Referer with a 302 back to that page. That
Post/Redirect/Get step is meant for plain HTML form posts, but it also
caught GET navigations: a link to a `#[get]` endpoint that returns a
file downloaded the linking page instead, and a callback endpoint
reached by a redirect was bounced back to the page it came from.

Only apply the redirect to POST requests. HTML forms can only submit
GET or POST, and a GET navigation should get the response itself.

Refs DioxusLabs#5445, DioxusLabs#5428

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fullstack endpoint ByteStream response replaced by referer page data for a download link

1 participant