upgrades: fix unsafe redirect errors in receipt/payment actions.
This commit is contained in:
@@ -41,12 +41,12 @@ class UserUpgradesController < ApplicationController
|
|||||||
|
|
||||||
def receipt
|
def receipt
|
||||||
@user_upgrade = authorize UserUpgrade.find(params[:id])
|
@user_upgrade = authorize UserUpgrade.find(params[:id])
|
||||||
redirect_to @user_upgrade.receipt_url
|
redirect_to @user_upgrade.receipt_url, allow_other_host: true
|
||||||
end
|
end
|
||||||
|
|
||||||
def payment
|
def payment
|
||||||
@user_upgrade = authorize UserUpgrade.find(params[:id])
|
@user_upgrade = authorize UserUpgrade.find(params[:id])
|
||||||
redirect_to @user_upgrade.payment_url
|
redirect_to @user_upgrade.payment_url, allow_other_host: true
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|||||||
Reference in New Issue
Block a user