mirror of
https://github.com/curl/curl.git
synced 2026-08-03 19:40:29 +03:00
http: for basic+digest auth, do not engage on empty user+passwd
Since we have the quirky of empty credentials (the empty string for username and password) for Negotiate reactivated, we need to check for this when considering Basic and Digest auth. Verify a redirect to blank user+password in test 2208 Closes #22060
This commit is contained in:
parent
8c3ef95adf
commit
d2886c5ac4
4 changed files with 105 additions and 7 deletions
|
|
@ -73,6 +73,8 @@ bool Curl_creds_equal(struct Curl_creds *c1, struct Curl_creds *c2);
|
|||
/* Provides properties for creds or, if creds is NULL, the empty string */
|
||||
#define Curl_creds_has_user(c) ((c) && (c)->user[0])
|
||||
#define Curl_creds_has_passwd(c) ((c) && (c)->passwd[0])
|
||||
#define Curl_creds_has_user_or_pass(c) \
|
||||
((c) && ((c)->user[0] || (c)->passwd[0]))
|
||||
#define Curl_creds_has_oauth_bearer(c) ((c) && (c)->oauth_bearer[0])
|
||||
#define Curl_creds_has_sasl_service(c) ((c) && (c)->sasl_service[0])
|
||||
#define Curl_creds_user(c) ((c) ? (c)->user : "")
|
||||
|
|
|
|||
19
lib/http.c
19
lib/http.c
|
|
@ -347,8 +347,10 @@ fail:
|
|||
*
|
||||
* return TRUE if one was picked
|
||||
*/
|
||||
static bool pickoneauth(struct auth *pick, unsigned long mask)
|
||||
static bool pickoneauth(struct auth *pick, unsigned long mask,
|
||||
struct Curl_creds *creds)
|
||||
{
|
||||
bool have_user_pass = Curl_creds_has_user_or_pass(creds);
|
||||
bool picked;
|
||||
/* only deal with authentication we want */
|
||||
unsigned long avail = pick->avail & pick->want & mask;
|
||||
|
|
@ -356,20 +358,20 @@ static bool pickoneauth(struct auth *pick, unsigned long mask)
|
|||
|
||||
/* The order of these checks is highly relevant, as this will be the order
|
||||
of preference in case of the existence of multiple accepted types. */
|
||||
if(avail & CURLAUTH_NEGOTIATE)
|
||||
if(avail & CURLAUTH_NEGOTIATE) /* available on empty creds */
|
||||
pick->picked = CURLAUTH_NEGOTIATE;
|
||||
#ifndef CURL_DISABLE_BEARER_AUTH
|
||||
else if(avail & CURLAUTH_BEARER)
|
||||
else if((avail & CURLAUTH_BEARER) && Curl_creds_has_oauth_bearer(creds))
|
||||
pick->picked = CURLAUTH_BEARER;
|
||||
#endif
|
||||
#ifndef CURL_DISABLE_DIGEST_AUTH
|
||||
else if(avail & CURLAUTH_DIGEST)
|
||||
else if((avail & CURLAUTH_DIGEST) && have_user_pass)
|
||||
pick->picked = CURLAUTH_DIGEST;
|
||||
#endif
|
||||
else if(avail & CURLAUTH_NTLM)
|
||||
pick->picked = CURLAUTH_NTLM;
|
||||
#ifndef CURL_DISABLE_BASIC_AUTH
|
||||
else if(avail & CURLAUTH_BASIC)
|
||||
else if((avail & CURLAUTH_BASIC) && have_user_pass)
|
||||
pick->picked = CURLAUTH_BASIC;
|
||||
#endif
|
||||
#ifndef CURL_DISABLE_AWS
|
||||
|
|
@ -568,7 +570,7 @@ CURLcode Curl_http_auth_act(struct Curl_easy *data)
|
|||
if(data->state.creds &&
|
||||
((data->req.httpcode == 401) ||
|
||||
(data->req.authneg && data->req.httpcode < 300))) {
|
||||
pickhost = pickoneauth(&data->state.authhost, authmask);
|
||||
pickhost = pickoneauth(&data->state.authhost, authmask, data->state.creds);
|
||||
if(!pickhost)
|
||||
data->state.authproblem = TRUE;
|
||||
else
|
||||
|
|
@ -586,7 +588,8 @@ CURLcode Curl_http_auth_act(struct Curl_easy *data)
|
|||
((data->req.httpcode == 407) ||
|
||||
(data->req.authneg && data->req.httpcode < 300))) {
|
||||
pickproxy = pickoneauth(&data->state.authproxy,
|
||||
authmask & ~CURLAUTH_BEARER);
|
||||
authmask & ~CURLAUTH_BEARER,
|
||||
conn->http_proxy.creds);
|
||||
if(!pickproxy)
|
||||
data->state.authproblem = TRUE;
|
||||
else
|
||||
|
|
@ -699,10 +702,12 @@ static CURLcode output_auth_headers(struct Curl_easy *data,
|
|||
if(
|
||||
#ifndef CURL_DISABLE_PROXY
|
||||
(proxy && conn->http_proxy.creds &&
|
||||
Curl_creds_has_user_or_pass(conn->http_proxy.creds) &&
|
||||
!Curl_checkProxyheaders(data, conn,
|
||||
STRCONST("Proxy-authorization"))) ||
|
||||
#endif
|
||||
(!proxy && data->state.creds &&
|
||||
Curl_creds_has_user_or_pass(data->state.creds) &&
|
||||
!Curl_checkheaders(data, STRCONST("Authorization")))) {
|
||||
auth = "Basic";
|
||||
result = http_output_basic(data, conn, proxy);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue