All fixes

Fix an open redirect on your login page

open-redirect-login

Your login page forwards to whatever URL its redirect parameter names, so a phishing link can wear your domain and land on an attacker's page.

Why this matters

Your login page redirects users to any URL via a parameter. This aids phishing by lending your domain's trust to attacker-controlled URLs, but is not direct system exploitation.

Next.js

  1. 1 Validate the callback URL in your auth handler
typescript
const callbackUrl = searchParams.get('callbackUrl') || '/dashboard';
const url = new URL(callbackUrl, process.env.NEXTAUTH_URL);
// Only redirect to same origin
if (url.origin !== new URL(process.env.NEXTAUTH_URL).origin) {
  redirect('/dashboard');
}
redirect(callbackUrl);

Does your app still have this?

Scan your domain