mirror of
https://github.com/curl/curl.git
synced 2026-08-25 01:33:31 +03:00
http: prevent custom Authorization headers in redirects
... unless CURLOPT_UNRESTRICTED_AUTH is set to allow them. This matches how curl already handles Authorization headers created internally. Note: this changes behavior slightly, for the sake of reducing mistakes. Added test 317 and 318 to verify. Reported-by: Craig de Stigter Bug: https://curl.haxx.se/docs/adv_2018-b3bf.html
This commit is contained in:
parent
993dd5651a
commit
af32cd3859
7 changed files with 212 additions and 5 deletions
10
lib/http.c
10
lib/http.c
|
|
@ -714,7 +714,7 @@ Curl_http_output_auth(struct connectdata *conn,
|
|||
if(!data->state.this_is_a_follow ||
|
||||
conn->bits.netrc ||
|
||||
!data->state.first_host ||
|
||||
data->set.http_disable_hostname_check_before_authentication ||
|
||||
data->set.allow_auth_to_other_hosts ||
|
||||
strcasecompare(data->state.first_host, conn->host.name)) {
|
||||
result = output_auth_headers(conn, authhost, request, path, FALSE);
|
||||
}
|
||||
|
|
@ -1636,6 +1636,14 @@ CURLcode Curl_add_custom_headers(struct connectdata *conn,
|
|||
checkprefix("Transfer-Encoding:", headers->data))
|
||||
/* HTTP/2 doesn't support chunked requests */
|
||||
;
|
||||
else if(checkprefix("Authorization:", headers->data) &&
|
||||
/* be careful of sending this potentially sensitive header to
|
||||
other hosts */
|
||||
(data->state.this_is_a_follow &&
|
||||
data->state.first_host &&
|
||||
!data->set.allow_auth_to_other_hosts &&
|
||||
!strcasecompare(data->state.first_host, conn->host.name)))
|
||||
;
|
||||
else {
|
||||
CURLcode result = Curl_add_bufferf(req_buffer, "%s\r\n",
|
||||
headers->data);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue