Skip to content
← All rules
SecurityWeb security

security/no-unsafe-redirect

Redirect only to fixed local paths or parsed URLs checked against an exact visible origin allowlist.

redirectsuntrusted-inputallowlist
TypeScript
res.redirect(req.query.next);
Finding

Disallow request-controlled redirect targets.

Setup

Install the package, register its plugin factory, then enable the rule.

Install the package

pnpm add -D @scruple/security

Register the plugin

In scruple.config.ts, register the factory under the security namespace used by the rule ID.

import { security } from "@scruple/security";

plugins: {
  "security": security(),
},

Enable the rule

"security/no-unsafe-redirect": "warn"
Package
@scruple/security
Default threshold
0.9
Minimum confidence
0.75

Released under the MIT License.