mirror of
https://github.com/curl/curl.git
synced 2026-08-25 07:23:31 +03:00
General HTTP authentication cleanup and fixes
This commit is contained in:
parent
e7ee1ccf45
commit
fc6eff13b5
20 changed files with 636 additions and 309 deletions
|
|
@ -3,26 +3,27 @@ install:
|
|||
test:
|
||||
|
||||
EXTRA_DIST = test1 test108 test117 test127 test20 test27 test34 test46 \
|
||||
test10 test109 test118 test13 test200 test28 test36 test47 test100 \
|
||||
test11 test119 test14 test201 test29 test37 test5 test101 test110 \
|
||||
test12 test15 test202 test3 test4 test6 test102 test111 test120 test16 \
|
||||
test21 test30 test7 test103 test112 test121 test17 test22 test300 \
|
||||
test8 test104 test113 test122 test18 test23 test301 test9 test105 \
|
||||
test114 test123 test19 test24 test302 test43 test31 test106 test115 \
|
||||
test124 test190 test25 test303 test44 test38 test107 test116 test125 \
|
||||
test2 test26 test33 test45 test126 test304 test39 test32 test128 \
|
||||
test48 test306 test130 test131 test132 test133 test134 test135 test305 \
|
||||
test49 test50 test51 test52 test53 test54 test55 test56 test500 \
|
||||
test501 test502 test503 test504 test136 test57 test137 test138 test58 \
|
||||
test139 test140 test141 test59 test60 test61 test142 test143 test62 \
|
||||
test63 test64 test65 test66 test144 test145 test67 test68 test41 \
|
||||
test40 test42 test69 test70 test71 test72 test73 test146 test505 \
|
||||
test74 test75 test76 test77 test78 test147 test148 test506 test79 \
|
||||
test80 test81 test82 test83 test84 test85 test86 test87 test507 \
|
||||
test149 test88 test89 test90 test508 test91 test92 test203 test93 \
|
||||
test94 test95 test509 test510 test97 test98 test99 test150 test151 \
|
||||
test152 test153 test154 test155 test156 test157 test158 test159 test511 \
|
||||
test160 test161 test162 test163 test164 test512 test165 test166
|
||||
test10 test109 test118 test13 test200 test28 test36 test47 test100 \
|
||||
test11 test119 test14 test201 test29 test37 test5 test101 test110 \
|
||||
test12 test15 test202 test3 test4 test6 test102 test111 test120 \
|
||||
test16 test21 test30 test7 test103 test112 test121 test17 test22 \
|
||||
test300 test8 test104 test113 test122 test18 test23 test301 test9 \
|
||||
test105 test114 test123 test19 test24 test302 test43 test31 test106 \
|
||||
test115 test124 test190 test25 test303 test44 test38 test107 test116 \
|
||||
test125 test2 test26 test33 test45 test126 test304 test39 test32 \
|
||||
test128 test48 test306 test130 test131 test132 test133 test134 \
|
||||
test135 test305 test49 test50 test51 test52 test53 test54 test55 \
|
||||
test56 test500 test501 test502 test503 test504 test136 test57 test137 \
|
||||
test138 test58 test139 test140 test141 test59 test60 test61 test142 \
|
||||
test143 test62 test63 test64 test65 test66 test144 test145 test67 \
|
||||
test68 test41 test40 test42 test69 test70 test71 test72 test73 \
|
||||
test146 test505 test74 test75 test76 test77 test78 test147 test148 \
|
||||
test506 test79 test80 test81 test82 test83 test84 test85 test86 \
|
||||
test87 test507 test149 test88 test89 test90 test508 test91 test92 \
|
||||
test203 test93 test94 test95 test509 test510 test97 test98 test99 \
|
||||
test150 test151 test152 test153 test154 test155 test156 test157 \
|
||||
test158 test159 test511 test160 test161 test162 test163 test164 \
|
||||
test512 test165 test166 test167 test168 test169
|
||||
|
||||
# The following tests have been removed from the dist since they no longer
|
||||
# work. We need to fix the test suite's FTPS server first, then bring them
|
||||
|
|
|
|||
|
|
@ -32,7 +32,7 @@ HTTP with proxy athorization
|
|||
</strip>
|
||||
<protocol>
|
||||
GET http://we.want.that.site.com/16 HTTP/1.1
|
||||
Proxy-authorization: Basic ZmFrZUB1c2VyOqenp2xvb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29uZw==
|
||||
Proxy-Authorization: Basic ZmFrZUB1c2VyOqenp2xvb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29vb29uZw==
|
||||
Host: we.want.that.site.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
|
|
|||
62
tests/data/test167
Normal file
62
tests/data/test167
Normal file
|
|
@ -0,0 +1,62 @@
|
|||
# Server-side
|
||||
<reply>
|
||||
<data>
|
||||
HTTP/1.1 401 Authorization Required swsclose
|
||||
WWW-Authenticate: Digest realm="weirdorealm", nonce="12345"
|
||||
|
||||
</data>
|
||||
|
||||
<data1000>
|
||||
HTTP/1.1 200 OK swsclose
|
||||
Server: no
|
||||
|
||||
Nice auth sir!
|
||||
</data1000>
|
||||
|
||||
<datacheck>
|
||||
HTTP/1.1 401 Authorization Required swsclose
|
||||
WWW-Authenticate: Digest realm="weirdorealm", nonce="12345"
|
||||
|
||||
HTTP/1.1 200 OK swsclose
|
||||
Server: no
|
||||
|
||||
Nice auth sir!
|
||||
</datacheck>
|
||||
</reply>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
http
|
||||
</server>
|
||||
<name>
|
||||
HTTP with proxy-requiring-Basic to site-requiring-Digest
|
||||
</name>
|
||||
<command>
|
||||
http://data.from.server.requiring.digest.hohoho.com/167 --proxy http://%HOSTIP:%HOSTPORT --proxy-user foo:bar --digest --user digest:alot
|
||||
</command>
|
||||
</test>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<strip>
|
||||
^User-Agent: curl/.*
|
||||
</strip>
|
||||
<protocol>
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/167 HTTP/1.1
|
||||
Proxy-Authorization: Basic Zm9vOmJhcg==
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b zlib/1.1.4 c-ares/1.2.0 libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/167 HTTP/1.1
|
||||
Proxy-Authorization: Basic Zm9vOmJhcg==
|
||||
Authorization: Digest username="digest", realm="weirdorealm", nonce="12345", uri="/167", response="13c7c02a252cbe1c46d8669898a3be26"
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b zlib/1.1.4 c-ares/1.2.0 libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
</protocol>
|
||||
</verify>
|
||||
82
tests/data/test168
Normal file
82
tests/data/test168
Normal file
|
|
@ -0,0 +1,82 @@
|
|||
# Server-side
|
||||
<reply>
|
||||
|
||||
# this is returned first since we get no proxy-auth
|
||||
<data>
|
||||
HTTP/1.1 407 Authorization Required to proxy me my dear swsclose
|
||||
Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345"
|
||||
|
||||
And you should ignore this data.
|
||||
</data>
|
||||
|
||||
# then this is returned since we get no server-auth
|
||||
<data1000>
|
||||
HTTP/1.1 401 Authorization to the remote host as well swsbounce swsclose
|
||||
WWW-Authenticate: Digest realm="realmweirdo", nonce="123456"
|
||||
|
||||
you should ignore this data too
|
||||
</data1000>
|
||||
|
||||
<data1001>
|
||||
HTTP/1.1 200 OK swsclose
|
||||
Server: no
|
||||
|
||||
Nice auth sir!
|
||||
</data1001>
|
||||
|
||||
<datacheck>
|
||||
HTTP/1.1 407 Authorization Required to proxy me my dear swsclose
|
||||
Proxy-Authenticate: Digest realm="weirdorealm", nonce="12345"
|
||||
|
||||
HTTP/1.1 401 Authorization to the remote host as well swsbounce swsclose
|
||||
WWW-Authenticate: Digest realm="realmweirdo", nonce="123456"
|
||||
|
||||
HTTP/1.1 200 OK swsclose
|
||||
Server: no
|
||||
|
||||
Nice auth sir!
|
||||
</datacheck>
|
||||
</reply>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
http
|
||||
</server>
|
||||
<name>
|
||||
HTTP with proxy-requiring-Digest to site-requiring-Digest
|
||||
</name>
|
||||
<command>
|
||||
http://data.from.server.requiring.digest.hohoho.com/168 --proxy http://%HOSTIP:%HOSTPORT --proxy-user foo:bar --proxy-digest --digest --user digest:alot
|
||||
</command>
|
||||
</test>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<strip>
|
||||
^User-Agent: curl/.*
|
||||
</strip>
|
||||
<protocol>
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/168 HTTP/1.1
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b zlib/1.1.4 c-ares/1.2.0 libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/168 HTTP/1.1
|
||||
Proxy-Authorization: Digest username="digest", realm="weirdorealm", nonce="12345", uri="/168", response="4e79e4fc104ef1f16ab4567e1ad4dede"
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b zlib/1.1.4 c-ares/1.2.0 libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/168 HTTP/1.1
|
||||
Proxy-Authorization: Digest username="digest", realm="weirdorealm", nonce="12345", uri="/168", response="4e79e4fc104ef1f16ab4567e1ad4dede"
|
||||
Authorization: Digest username="digest", realm="realmweirdo", nonce="123456", uri="/168", response="ca87f2d768a231e2d637a55698d5c416"
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b ipv6 zlib/1.1.4 GSS libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
</protocol>
|
||||
</verify>
|
||||
107
tests/data/test169
Normal file
107
tests/data/test169
Normal file
|
|
@ -0,0 +1,107 @@
|
|||
# Server-side
|
||||
<reply>
|
||||
|
||||
# this is returned first since we get no proxy-auth
|
||||
<data>
|
||||
HTTP/1.1 407 Authorization Required to proxy me my dear swsclose
|
||||
Proxy-Authenticate: NTLM
|
||||
|
||||
And you should ignore this data.
|
||||
</data>
|
||||
|
||||
# then this is returned since we get no server-auth
|
||||
<data1000>
|
||||
HTTP/1.1 200 Authorizated fine
|
||||
Content-Length: 27
|
||||
|
||||
Welcome to the end station
|
||||
</data1000>
|
||||
|
||||
<data1001>
|
||||
HTTP/1.1 407 NTLM type-1 received sending back type-2
|
||||
Server: Microsoft-IIS/5.0
|
||||
Content-Length: 34
|
||||
Content-Type: text/html; charset=iso-8859-1
|
||||
Proxy-Authenticate: NTLM TlRMTVNTUAACAAAAAgACADAAAAAGgoEAc51AYVDgyNcAAAAAAAAAAG4AbgAyAAAAQ0MCAAQAQwBDAAEAEgBFAEwASQBTAEEAQgBFAFQASAAEABgAYwBjAC4AaQBjAGUAZABlAHYALgBuAHUAAwAsAGUAbABpAHMAYQBiAGUAdABoAC4AYwBjAC4AaQBjAGUAZABlAHYALgBuAHUAAAAAAA==
|
||||
|
||||
This is not the real page either!
|
||||
</data1001>
|
||||
|
||||
# This is supposed to be returned when the server gets the second
|
||||
# Authorization: NTLM line passed-in from the client
|
||||
<data1002>
|
||||
HTTP/1.1 401 You now need to authenticate with the host
|
||||
Server: Microsoft-IIS/5.0
|
||||
WWW-Authenticate: Digest realm="r e a l m", nonce="abcdef"
|
||||
Content-Length: 40
|
||||
Content-Type: text/html; charset=iso-8859-1
|
||||
|
||||
We have not authenticated with the server yet
|
||||
</data1002>
|
||||
|
||||
<datacheck>
|
||||
HTTP/1.1 407 NTLM type-1 received sending back type-2
|
||||
Server: Microsoft-IIS/5.0
|
||||
Content-Length: 34
|
||||
Content-Type: text/html; charset=iso-8859-1
|
||||
Proxy-Authenticate: NTLM TlRMTVNTUAACAAAAAgACADAAAAAGgoEAc51AYVDgyNcAAAAAAAAAAG4AbgAyAAAAQ0MCAAQAQwBDAAEAEgBFAEwASQBTAEEAQgBFAFQASAAEABgAYwBjAC4AaQBjAGUAZABlAHYALgBuAHUAAwAsAGUAbABpAHMAYQBiAGUAdABoAC4AYwBjAC4AaQBjAGUAZABlAHYALgBuAHUAAAAAAA==
|
||||
|
||||
HTTP/1.1 401 You now need to authenticate with the host
|
||||
Server: Microsoft-IIS/5.0
|
||||
WWW-Authenticate: Digest realm="r e a l m", nonce="abcdef"
|
||||
Content-Length: 40
|
||||
Content-Type: text/html; charset=iso-8859-1
|
||||
|
||||
HTTP/1.1 200 Authorizated fine
|
||||
Content-Length: 27
|
||||
|
||||
Welcome to the end station
|
||||
</datacheck>
|
||||
</reply>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
http
|
||||
</server>
|
||||
# NTLM only works if we are built with SSL
|
||||
<features>
|
||||
SSL
|
||||
</features>
|
||||
<name>
|
||||
HTTP with proxy-requiring-NTLM to site-requiring-Digest
|
||||
</name>
|
||||
<command>
|
||||
http://data.from.server.requiring.digest.hohoho.com/169 --proxy http://%HOSTIP:%HOSTPORT --proxy-user foo:bar --proxy-ntlm --digest --user digest:alot
|
||||
</command>
|
||||
</test>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<strip>
|
||||
^User-Agent: curl/.*
|
||||
</strip>
|
||||
<protocol>
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/169 HTTP/1.1
|
||||
Proxy-Authorization: NTLM TlRMTVNTUAABAAAAAgIAAAAAAAAgAAAAAAAAACAAAAA=
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b ipv6 zlib/1.1.4 GSS libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/169 HTTP/1.1
|
||||
Proxy-Authorization: NTLM TlRMTVNTUAADAAAAGAAYAEMAAAAYABgAWwAAAAAAAABAAAAAAwADAEAAAAAAAAAAQwAAAAAAAABzAAAAAYIAAGZvb4P6B+XVQ6vQsx3DfDXUVhd9436GAxPu0IYcl2Z7LxHmNeOAWQ+vxUmhuCFJBUgXCQ==
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b ipv6 zlib/1.1.4 GSS libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
GET http://data.from.server.requiring.digest.hohoho.com/169 HTTP/1.1
|
||||
Authorization: Digest username="digest", realm="r e a l m", nonce="abcdef", uri="/169", response="95d48591985a03c4b49cb962aa7bd3e6"
|
||||
User-Agent: curl/7.12.0-CVS (i686-pc-linux-gnu) libcurl/7.12.0-CVS OpenSSL/0.9.6b ipv6 zlib/1.1.4 GSS libidn/0.4.3
|
||||
Host: data.from.server.requiring.digest.hohoho.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
||||
</protocol>
|
||||
</verify>
|
||||
|
|
@ -49,7 +49,7 @@ moo
|
|||
<verify>
|
||||
<protocol>
|
||||
CONNECT 127.0.0.1:8433 HTTP/1.0
|
||||
Proxy-authorization: Basic dGVzdDppbmc=
|
||||
Proxy-Authorization: Basic dGVzdDppbmc=
|
||||
|
||||
GET /503 HTTP/1.1
|
||||
Authorization: Basic dGVzdDppbmc=
|
||||
|
|
|
|||
|
|
@ -32,7 +32,7 @@ http://we.want.that.site.com/63
|
|||
</strip>
|
||||
<protocol>
|
||||
GET http://we.want.that.site.com/63 HTTP/1.1
|
||||
Proxy-authorization: Basic ZmFrZTp1c2Vy
|
||||
Proxy-Authorization: Basic ZmFrZTp1c2Vy
|
||||
Host: we.want.that.site.com
|
||||
Pragma: no-cache
|
||||
Accept: */*
|
||||
|
|
|
|||
|
|
@ -45,7 +45,7 @@ http://%HOSTIP:%HOSTPORT/we/want/that/page/80 -p -x %HOSTIP:%HOSTPORT --user iam
|
|||
</strip>
|
||||
<protocol>
|
||||
CONNECT 127.0.0.1:8999 HTTP/1.0
|
||||
Proxy-authorization: Basic eW91YXJlOnlvdXJzZWxm
|
||||
Proxy-Authorization: Basic eW91YXJlOnlvdXJzZWxm
|
||||
User-Agent: curl/7.10.7-pre2 (i686-pc-linux-gnu) libcurl/7.10.7-pre2 OpenSSL/0.9.7a zlib/1.1.3
|
||||
|
||||
GET /we/want/that/page/80 HTTP/1.1
|
||||
|
|
|
|||
|
|
@ -35,7 +35,7 @@ http://%HOSTIP:%HOSTPORT/82 --proxy-user testuser:testpass -x http://%HOSTIP:%HO
|
|||
</strip>
|
||||
<protocol>
|
||||
GET http://127.0.0.1:8999/82 HTTP/1.1
|
||||
Proxy-authorization: Basic dGVzdHVzZXI6dGVzdHBhc3M=
|
||||
Proxy-Authorization: Basic dGVzdHVzZXI6dGVzdHBhc3M=
|
||||
User-Agent: curl/7.10.6-pre1 (i686-pc-linux-gnu) libcurl/7.10.6-pre1 OpenSSL/0.9.7a ipv6 zlib/1.1.3
|
||||
Host: 127.0.0.1:8999
|
||||
Pragma: no-cache
|
||||
|
|
|
|||
|
|
@ -34,7 +34,7 @@ http://%HOSTIP:%HOSTPORT/we/want/that/page/85 -x %HOSTIP:%HOSTPORT --user iam:my
|
|||
</strip>
|
||||
<protocol>
|
||||
GET http://127.0.0.1:8999/we/want/that/page/85 HTTP/1.1
|
||||
Proxy-authorization: Basic dGVzdGluZzp0aGlz
|
||||
Proxy-Authorization: Basic dGVzdGluZzp0aGlz
|
||||
Authorization: Basic aWFtOm15c2VsZg==
|
||||
User-Agent: curl/7.10.7-pre2 (i686-pc-linux-gnu) libcurl/7.10.7-pre2 OpenSSL/0.9.7a zlib/1.1.3
|
||||
Host: 127.0.0.1:8999
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue