We are sunsetting Hakiri on January 31 2022. To learn more please refer to this document.

Discovered almost 5 years ago
Source: static code analysis
Category: Redirect
Confidence level: Weak


Possible unprotected redirect



redirect_to(path("#{Invite.find_by(:invite_key => params[:token]).topics.first.relative_url}"))

Category description: Sometimes redirect_to can be used with a user-supplied value that may allow the attacker to change the :host option and load a malicious script from a third party website.

Solution: fix the issue in app/controllers/invites_controller.rb or mark it as false positive.