synapse-product/changelog.d/6063.bugfix
Andrew Morgan aeb40f355c
Ensure email validation link parameters are URL-encoded (#6063)
The validation links sent via email had their query parameters inserted without any URL-encoding. Surprisingly this didn't seem to cause any issues, but if a user were to put a `/` in their client_secret it could lead to problems.
2019-09-20 10:46:59 +01:00

1 line
66 B
Plaintext

Ensure query parameters in email validation links are URL-encoded.