Submit login credentials URL-encoded and accept them only in that encoding, so AppSec can redact them

This commit is contained in:
Viktor Liu
2026-09-23 13:09:03 +02:00
parent d77091cdbe
commit 469973f59d
4 changed files with 81 additions and 5 deletions
+1 -1
View File
File diff suppressed because one or more lines are too long
+6 -4
View File
@@ -52,16 +52,18 @@ function App() {
setError(null);
setSubmitting(method);
const formData = new FormData();
// URL-encoded, not FormData: the proxy only accepts credentials in this
// encoding, the one it can redact before mirroring a request to AppSec.
const body = new URLSearchParams();
if (method === "password") {
formData.append(methods.password!, value);
body.append(methods.password!, value);
} else {
formData.append(methods.pin!, value);
body.append(methods.pin!, value);
}
fetch(globalThis.location.href, {
method: "POST",
body: formData,
body,
redirect: "manual",
})
.then((res) => {