Skip to content

Commit 9835707

Browse files
committed
Merge remote-tracking branch 'origin/master' into PEGASUS-935-investigate-reported-sso-open-redirect-vulnerabili
2 parents fdfc1f1 + 79eff3a commit 9835707

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

src/app/code/community/Zendesk/Zendesk/controllers/Adminhtml/ZendeskController.php

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -135,6 +135,7 @@ public function authenticateAction()
135135
if(!Mage::getStoreConfig('zendesk/sso/enabled')) {
136136
Mage::getSingleton('adminhtml/session')->addError(Mage::helper('zendesk')->__('Single sign-on disabled.'));
137137
$this->_redirect(Mage::getSingleton('admin/session')->getUser()->getStartupPageUrl());
138+
return $this;
138139
}
139140

140141
$domain = Mage::getStoreConfig('zendesk/general/domain');
@@ -144,11 +145,13 @@ public function authenticateAction()
144145
if(!Zend_Validate::is($domain, 'NotEmpty')) {
145146
Mage::getSingleton('adminhtml/session')->addError(Mage::helper('zendesk')->__('Zendesk domain not set. Please add this to the settings page.'));
146147
$this->_redirect(Mage::getSingleton('admin/session')->getUser()->getStartupPageUrl());
148+
return $this;
147149
}
148150

149151
if(!Zend_Validate::is($token, 'NotEmpty')) {
150152
Mage::getSingleton('adminhtml/session')->addError(Mage::helper('zendesk')->__('Zendesk SSO token not set. Please add this to the settings page.'));
151153
$this->_redirect(Mage::getSingleton('admin/session')->getUser()->getStartupPageUrl());
154+
return $this;
152155
}
153156

154157
$now = time();

0 commit comments

Comments
 (0)