Self-hosted web view login cookie check fails for usernames containing `@` or spaces
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 82/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- ios, objective-c, swift
- Ambito
- authentication, mobile, mobile-dev
Direzione di ricerca
Inizia in WordPress/Classes/Utility/WebViewController/CookieJar.swift, in HTTPCookie.isWordPressLoggedIn(username:), che attualmente considera tutto ciò che precede il primo % come nome utente. Decodifica il valore del cookie con percent-decoding (PHP mappa anche gli spazi su +) e dividilo usando |, come fa isWordPressLoggedInAtomic(username:). Verifica che AuthenticationService.loadAuthCookiesForSelfHosted non effettui più un nuovo POST a wp-login.php per nomi utente come [email protected] e john doe.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Found while reviewing #26103. Pre-existing — not introduced by that PR, and unchanged by #26106 and #26104.
The logged-in cookie check for self-hosted sites never matches when the username contains a character that PHP URL-encodes, so the app logs in again before every authenticated web view load.
Root cause
HTTPCookie.isWordPressLoggedIn(username:) takes the username to be everything before the first % in the cookie value:
WordPress sets the cookie value to username|expiration|token|hmac and PHP's setcookie() URL-encodes it, so the check relies on the first | arriving as %7C. An encoded character inside the username breaks that:
| Username | Cookie value | Parsed username | Match |
|---|---|---|---|
admin |
admin%7C… |
admin |
✅ |
[email protected] |
user%40example.com%7C… |
user |
❌ |
john doe |
john+doe%7C… |
john+doe |
❌ |
Impact
AuthenticationService.loadAuthCookiesForSelfHosted treats a failed check as "no cookie" and POSTs the username and password to wp-login.php again:
This affects sites that RequestAuthenticator authenticates with .siteLogin credentials. The login itself still succeeds, so the cost is an extra login round-trip — and a new session on the site — before each authenticated load, rather than a visible failure.
WordPress.com usernames are normally limited to lowercase letters and numbers, so the same predicate is not expected to misfire on the WordPress.com path.
Verification
Confirmed with a Foundation probe (macOS 27.0.1): HTTPCookie.cookies(withResponseHeaderFields:for:) keeps the value percent-encoded, and the predicate returns false for [email protected] and john doe.
The cookie values in the probe were built from WordPress's cookie format. We have not reproduced this against a live self-hosted site.
Suggested fix
Percent-decode the value before parsing — PHP's urlencode also turns spaces into + — and split on |, as isWordPressLoggedInAtomic(username:) already does.
- Lingua principale
- Swift
- Stelle
- 3.9k
- Fork
- 1.2k
- Merge medio
- 1g 18h
- PR unite (30g)
- 56
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di wordpress-mobile/WordPress-iOS
-
[Type] Tech Debt Site Creation
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
wordpress-mobile/WordPress-iOS#26113 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[Type] Tech Debt
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
wordpress-mobile/WordPress-iOS#26112 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
wordpress-mobile/WordPress-iOS#25657 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Rename Stats Insight cards for clarityForse già presa @amitraj2203 l’ha presa 55 giorni fa. Aperta[Pri] Low [Type] Enhancement Stats
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
wordpress-mobile/WordPress-iOS#23015 · 2 commenti · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
Remove Google Plus mentionsForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta[Type] Tech Debt Good First Issue Sharing
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
wordpress-mobile/WordPress-iOS#20142 · 15 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di wordpress-mobile/WordPress-iOS
Issue simili
-
#️⃣ REX and feebacks 🔍 triage 🧑💻 Developer eXperience 🧰 library
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Orange-OpenSource/ouds-ios#1795 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
RodnaPamet/agrent-ios#172 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
bug iOS 🍎 ui/ux
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
MerginMaps/mobile#4744 ·
I maintainer di solito rispondono entro 1 giorno
-
bug milestone-qa mobile
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
lognorman20/monaco#3519 ·