2017-07-08 03:18:03 +02:00
|
|
|
# http://flask.pocoo.org/snippets/62/
|
|
|
|
|
2017-07-14 06:28:00 +02:00
|
|
|
try:
|
|
|
|
from urllib.parse import urlparse, urljoin
|
|
|
|
except ImportError:
|
|
|
|
from urlparse import urlparse, urljoin
|
2017-07-08 03:18:03 +02:00
|
|
|
from flask import request, url_for, redirect
|
|
|
|
|
|
|
|
|
|
|
|
def is_safe_url(target):
|
|
|
|
ref_url = urlparse(request.host_url)
|
|
|
|
test_url = urlparse(urljoin(request.host_url, target))
|
|
|
|
return test_url.scheme in ('http', 'https') and ref_url.netloc == test_url.netloc
|
|
|
|
|
|
|
|
|
|
|
|
def get_redirect_target():
|
|
|
|
for target in request.values.get('next'), request.referrer:
|
|
|
|
if not target:
|
|
|
|
continue
|
|
|
|
if is_safe_url(target):
|
|
|
|
return target
|
|
|
|
|
|
|
|
|
|
|
|
def redirect_back(endpoint, **values):
|
|
|
|
target = request.form['next']
|
|
|
|
if not target or not is_safe_url(target):
|
|
|
|
target = url_for(endpoint, **values)
|
|
|
|
return redirect(target)
|