Recursive back URL parameter
Prerequisites
- I understand and accept the project's code of conduct.
- I have already searched in existing issues and found no previous report of this bug.
Describe the bug and add attachments
Discovering:
We get infinite recursion URL in webserver log, like GET /fr/connexion?back=https://example.com/fr/connexion?back=https%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fauthor%2F14303-white-paula%3Fpage%3D6
Root cause:
classes/controller/FrontController.php:1549
'current_url' => $this->context->shop->getBaseURL(true, false) . $_SERVER['REQUEST_URI'],This builds the current_url template variable by blindly concatenating the raw request URI — including any query string the current page already has, back=... included. It's consumed by modules/ps_customersignin/ps_customersignin.tpl:30:
href="{$urls.pages.authentication}?back={$urls.current_url}"That "Sign in" link is in the header, rendered on every page a visitor isn't logged in on — including the login page itself. So on /connexion?back=X, the page's own current_url is .../connexion?back=X, and the "Sign in" link on that page points to /connexion?back=.../connexion?back=X — one layer deeper, single-urlencoded. A crawler treats each hop as a distinct URL and keeps following it, growing the URL by one more anmeldung?back= wrapper every time. That's a classic self-inflicted crawler trap, it's pure recursive link generation.
Fix:
Strip any pre-existing back parameter when building current_url, so the chain can't nest. This also happens to be correct for the other two consumers of current_url (og:url and JSON-LD url in microdata-jsonld.tpl) — a canonical/OG URL shouldn't carry a transient redirect param anyway.
Steps to reproduce
If you are using ps_customersignin, you will probable find this pattern in the Apache access log.
To reproduce without looking at the server log:
- Go to the logline page with ps_customersignin module activated
- Click on the
Log in to your customer accountlink - Each click, the URL gets longer with an additional recursive back parameter
Expected behavior
back parameters should never be recursive.
Actual Result
No response
PrestaShop version where the bug happens
8.1.3
How have you installed PrestaShop
I'm using git clone on a modified private github repo
PHP version(s) where the bug happened
8.1
Your company or customer's name goes here (if applicable).
No response
Source: PrestaShop/PrestaShop