Invalid cookie headers being returned
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 25/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- perl
- Ambito
- networking
Direzione di ricerca
Inizia eseguendo il caso di test Perl/Plack fornito e analizzando come vengono assemblati gli header della risposta tramite HTTP::Message e HTTP::Headers::Fast. Verifica come vengono rappresentati e raggruppati più valori Set-Cookie. Il lavoro è completato quando i valori Set-Cookie rimangono separati e la gestione dei cookie duplicati corrisponde alle specifiche dei cookie citate.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hi there,
I think this might belong against HTTP::Headers::Fast, but it's popping up in a client's Plack stack, so I thought I would start here first. This is a small test case:
#!/usr/bin/env perl
use Test::Most;
use Plack::Response;
use Plack::Test;
my $response = Plack::Response->new(200);
$response->content('Hello World');
$response->cookies->{foo} = {
value => 'test',
expires => time + 24 * 60 * 60,
secure => 1,
};
$response->cookies->{bar} = {
value => 'test2',
expires => time + 24 * 60 * 60,
secure => 1,
};
$response->headers->push_header( 'Set-Cookie', 'foo=that' );
# traditional - named params
test_psgi
app => $response->to_app,
client => sub {
my $cb = shift;
my $req = HTTP::Request->new( GET => "http://localhost/hello" );
my $res = $cb->($req);
like $res->content, qr/Hello World/;
explain scalar $res->headers->header('Set-Cookie');
};
done_testing;
That final line prints:
foo=that, bar=test2; expires=Wed, 06-Jul-2022 12:27:13 GMT; secure, foo=test; expires=Wed, 06-Jul-2022 12:27:13 GMT; secure
Per the IETF spec, we have a couple of violations:
Origin servers SHOULD NOT fold multiple Set-Cookie header fields into a single header field. The usual mechanism for folding HTTP headers fields (i.e., as defined in [RFC2616]) might change the semantics of the Set-Cookie header field because the %x2C (",") character is used by Set-Cookie in a way that conflicts with such folding.
As a consequence of the above, in the last sentence of section 4.1.2, we find the following:
User agents ignore unrecognized cookie attributes (but not the entire cookie).
Because the header fields are joined on a comma, we have an invalid secure, attribute, which suggests that strict cookie parsers might accept the cookie, but ignore the strict attribute. This might be a serious security concern.
Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the same cookie-name. (See Section 5.2 for how user agents handle this case.)
In the above example, we have the cookie foo being set twice, with different values and attributes. This caused a serious authentication issue in our client's code.
Admittedly, this code is being used extensively and I'm unsure about a decent approach to solving it.
- Lingua principale
- Perl
- Stelle
- 32
- Fork
- 63
- Merge medio
- 5h 14m
- PR unite (30g)
- 1
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di libwww-perl/HTTP-Message
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
libwww-perl/HTTP-Message#228 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
libwww-perl/HTTP-Message#227 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 42/100
libwww-perl/HTTP-Message#216 ·
-
Please add a security policyAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 35/100
libwww-perl/HTTP-Message#207 · 1 commento ·
-
Decoding of deflate content-encoding doesn't respect max_body_sizeForse già presa @simbabque l’ha presa 524 giorni fa. Aperta
libwww-perl/HTTP-Message#206 · 1 commento · 1 assegnatario ·
Tutte le issue di libwww-perl/HTTP-Message
Issue simili
-
FOODTURE
Difficoltà 2/5 1-3 ore Idoneità per principianti 67/100
openfoodfacts/openfoodfacts-server#14853 ·
I maintainer di solito rispondono entro 1 giorno
-
Needs Triage
Difficoltà 2/5 Mezza giornata Idoneità per principianti 66/100
Perl/perl5#24913 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
gugod/App-perlbrew#879 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
RotherOSS/otobo#6205 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno