Problem/Motivation

The assurance method's step_up_login_url must be an absolute http(s) URL: BridgeController::trustedStepUpLoginUrl() requires a ^https?:// prefix and StepUpAuthorizeUrl::build() rejects non-absolute bases. When the integrating site provides its own step-up initiator route (a server-side page that starts the IdP authorize flow), the natural value is a site-relative path like /wl-oidc/step-up — but the current validation forces a per-environment absolute URL into what is otherwise environment-neutral exported configuration.

Proposed resolution

Accept a site-relative step_up_login_url in both places: a path starting with a single "/" (reject "//" network-path references, backslashes, and anything else) is same-origin by construction, so the existing open-redirect defense is not weakened — the query-supplied login_url stays ignored, exactly as today. StepUpAuthorizeUrl::build() appends acr_values to a relative base the same way it does to an absolute one. Absolute https URLs keep working unchanged.

User interface changes

The step_up_login_url form description mentions that a site-relative path is accepted.

Remaining tasks

Development happens on the project's GitHub repository (Wilkes-Liberty/file_gate); the PR will be cross-linked here for review. Kernel test coverage: relative path accepted with acr appended; "//evil.example" and "javascript:" rejected.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Status: Active » Fixed

Implemented and released in 1.6.0 (https://www.drupal.org/project/file_gate/releases/1.6.0).

step_up_login_url accepts a site-relative path with a single leading slash alongside absolute http(s) URLs. Validation is shared between the bridge controller and StepUpAuthorizeUrl so the two cannot drift: backslashes and control characters are rejected in every base, absolute bases must parse with a real host, network-path references (//host) are rejected, and a base that passes the trust check but fails URL assembly now fails closed instead of leaking through raw. The query-supplied login_url stays ignored, unchanged.

Development PR with kernel and unit coverage in both directions: https://github.com/Wilkes-Liberty/file_gate/pull/63

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.