From 630beba02eac72626e4bea1c0f4d81e17c2fec3e Mon Sep 17 00:00:00 2001 From: Xavier Morel Date: Fri, 19 Jun 2020 12:03:17 +0000 Subject: [PATCH] [FIX] website_links: incorrect uses of redirect Until Werkzeug 0.14, redirect() would resolve all URLs to absolute paths or even absolute URL, because relative paths were not valid according to the HTTP RFCs (though most browsers supported them). However RFC 7231 allows them, so Werkzeug 0.15 removes this rewrite on URLs, and `redirect('foo/bar')` now redirects *relative to the current URL* instead of the old `/foo/bar`. If `code` is not found, the link tracker loops on the current URL (`/r/{code}`) instead of redirecting to `/` as was intended. Going through uses of redirect() this seems to be the only problematic call site left, others either use absolute paths or they use URLs coming from the outside. Task 2254691 closes odoo/odoo#53327 X-original-commit: 3a6e079e54a6f973cfc96995a84a7fabff803f1c Signed-off-by: Xavier Morel (xmo) --- addons/website_links/controller/main.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/website_links/controller/main.py b/addons/website_links/controller/main.py index 35eac514391..b90c63a1a0e 100644 --- a/addons/website_links/controller/main.py +++ b/addons/website_links/controller/main.py @@ -38,4 +38,4 @@ class WebsiteUrl(http.Controller): if code: return request.render("website_links.graphs", code.link_id.read()[0]) else: - return werkzeug.utils.redirect('', 301) + return werkzeug.utils.redirect('/', 301)