Skip to content
This repository was archived by the owner on Apr 26, 2024. It is now read-only.

Commit 3dbfba0

Browse files
committed
Remove trailing slash ability from password reset's submit_token endpoint (#6074)
2 parents 9887aea + 7763dd3 commit 3dbfba0

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

changelog.d/6074.feature

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Prevent password reset's submit_token endpoint from accepting trailing slashes.

synapse/rest/client/v2_alpha/account.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -207,7 +207,7 @@ class PasswordResetSubmitTokenServlet(RestServlet):
207207
"""Handles 3PID validation token submission"""
208208

209209
PATTERNS = client_patterns(
210-
"/password_reset/(?P<medium>[^/]*)/submit_token/*$", releases=(), unstable=True
210+
"/password_reset/(?P<medium>[^/]*)/submit_token$", releases=(), unstable=True
211211
)
212212

213213
def __init__(self, hs):

0 commit comments

Comments
 (0)