It's really not a bad vulnerability, but it's not great either, so I'm
filing this publicly even though it's a security vulnerability, just
barely.
We're going to address this in our websites, starting here:
https://github.com/freelawproject/bigcases2/issues/342
Would it be helpful to do it upstream in Django itself instead/also? We
could probably help with that if so.
--
Ticket URL: <https://code.djangoproject.com/ticket/34763>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
* status: new => closed
* resolution: => invalid
Comment:
I can imagine situation when URLs in username are desirable. IMO, deciding
for users in such cases is not a framework job. We shouldn't be so caring.
--
Ticket URL: <https://code.djangoproject.com/ticket/34763#comment:1>