Skip to content

OFREP providers don't encode flagKey #1324

Open
@toddbaert

Description

@toddbaert

It seems to me that we aren't properly encoding the /{flagKey} path segment in OFREP requests here.

This means that flags with certain characters in them / for example, will cause errors, and potentially present security issues.

We should encode this segment.

cc @juanparadox

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsecuritysecurity related bugs/tasks

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions