Bugs in `Authorization: Bearer …` header parsing
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 38/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Stack tecnológico
- rust
- Área
- authentication
Línea de trabajo
Start at the headers::authorization::Bearer implementation and run the test_invalid_auth_header example from the issue. Check parsing of malformed values, restricted token characters, extra spaces, and case-insensitive auth schemes; done means invalid headers fail and valid tokens are returned without surrounding whitespace.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
The following test exposes a few issues in headers::authorization::Bearer:
#[cfg(test)]
mod tests {
#[test]
fn test_invalid_auth_header() {
// Malformed, should not parse.
let value = http::HeaderValue::from_str("Bearer foo, Bearer bar").unwrap();
use headers::authorization::Credentials;
let decoded = headers::authorization::Bearer::decode(&value);
println!("decoded = {:?}", decoded);
println!("if decoded succeeded, the token was: {:?}", decoded.as_ref().map(|b| b.token()));
// The header is malformed, so parsing should fail:
assert!(decoded.is_none());
}
}
Basically, Bearer's implementation will strip the leading string "Bearer " from the value, and return the remainder for as a token. This isn't valid according to the grammar for the Bearer authn scheme. (The grammar of the token itself is restricted to a certain set of characters, for example.) In fact, the code only checks that the header starts with Bearer in debug mode (as it is done w/ a debug_assert!), so in a release build, any value will parse, including, e.g., Basic <a basic headers' credentials>.
Even where the header is valid, and should parse, the .token() determines the token by simply removing "Bearer ".len() characters from the front of the header value, which itself is not correct: Bearer foobar (n.b., the double space; this is permitted by the grammar for the header, but is not part of the token) parses as it should, but .token() returns " foobar".
Last, the debug-mode-only debug_assert! asserts that the value starts with Bearer — but auth schemes in HTTP are case insensitive, so this too will reject valid inputs. (Note: the Basic auth-scheme parser shares its own version of this issue, too.)
- Lenguaje dominante
- Rust
- Estrellas
- 200
- Forks
- 107
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de hyperium/headers
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 78/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
-
Link support Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
Todos los issues de hyperium/headers
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
TheLarkInn/aipm#2413 ·
-
documentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
alexgorbatchev/simple-ptt#15 ·
-
tooling
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
-
todo:ticket
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
taikoxyz/taiko-mono#22168 · 1 comentario ·