Skip to content
This repository was archived by the owner on May 31, 2024. It is now read-only.

Commit a9a1d50

Browse files
asiragusafabpot
authored andcommitted
Avoid redirection to XHR URIs
1 parent c7a417a commit a9a1d50

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

Http/Firewall/ExceptionListener.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -194,7 +194,7 @@ private function startAuthentication(Request $request, AuthenticationException $
194194
protected function setTargetPath(Request $request)
195195
{
196196
// session isn't required when using HTTP basic authentication mechanism for example
197-
if ($request->hasSession() && $request->isMethodSafe()) {
197+
if ($request->hasSession() && $request->isMethodSafe() && !$request->isXmlHttpRequest()) {
198198
$request->getSession()->set('_security.'.$this->providerKey.'.target_path', $request->getUri());
199199
}
200200
}

0 commit comments

Comments
 (0)