Invalid cookie headers being returned
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 25/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 技術スタック
- perl
- 領域
- networking
調査の方向性
まず、提供された Perl/Plack テストケースを実行し、HTTP::Message と HTTP::Headers::Fast を通じてレスポンスヘッダーがどのように組み立てられるかを確認します。複数の Set-Cookie 値がどのように表現され、まとめられるかを確認してください。Set-Cookie 値が分離されたまま維持され、重複する Cookie の処理が引用されている Cookie 仕様に一致すれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Hi there,
I think this might belong against HTTP::Headers::Fast, but it's popping up in a client's Plack stack, so I thought I would start here first. This is a small test case:
#!/usr/bin/env perl
use Test::Most;
use Plack::Response;
use Plack::Test;
my $response = Plack::Response->new(200);
$response->content('Hello World');
$response->cookies->{foo} = {
value => 'test',
expires => time + 24 * 60 * 60,
secure => 1,
};
$response->cookies->{bar} = {
value => 'test2',
expires => time + 24 * 60 * 60,
secure => 1,
};
$response->headers->push_header( 'Set-Cookie', 'foo=that' );
# traditional - named params
test_psgi
app => $response->to_app,
client => sub {
my $cb = shift;
my $req = HTTP::Request->new( GET => "http://localhost/hello" );
my $res = $cb->($req);
like $res->content, qr/Hello World/;
explain scalar $res->headers->header('Set-Cookie');
};
done_testing;
That final line prints:
foo=that, bar=test2; expires=Wed, 06-Jul-2022 12:27:13 GMT; secure, foo=test; expires=Wed, 06-Jul-2022 12:27:13 GMT; secure
Per the IETF spec, we have a couple of violations:
Origin servers SHOULD NOT fold multiple Set-Cookie header fields into a single header field. The usual mechanism for folding HTTP headers fields (i.e., as defined in [RFC2616]) might change the semantics of the Set-Cookie header field because the %x2C (",") character is used by Set-Cookie in a way that conflicts with such folding.
As a consequence of the above, in the last sentence of section 4.1.2, we find the following:
User agents ignore unrecognized cookie attributes (but not the entire cookie).
Because the header fields are joined on a comma, we have an invalid secure, attribute, which suggests that strict cookie parsers might accept the cookie, but ignore the strict attribute. This might be a serious security concern.
Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the same cookie-name. (See Section 5.2 for how user agents handle this case.)
In the above example, we have the cookie foo being set twice, with different values and attributes. This caused a serious authentication issue in our client's code.
Admittedly, this code is being used extensively and I'm unsure about a decent approach to solving it.
- 主要言語
- Perl
- スター
- 32
- フォーク
- 63
- 平均マージ
- 5時間 14分
- マージ済み PR(30日)
- 1
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
libwww-perl/HTTP-Message のほかの issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
libwww-perl/HTTP-Message#228 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
libwww-perl/HTTP-Message#227 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 42/100
libwww-perl/HTTP-Message#216 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 35/100
libwww-perl/HTTP-Message#207 · コメント 1 件 ·
-
Decoding of deflate content-encoding doesn't respect max_body_size対応中かも @simbabque が 522 日前に担当しました。 オープン
libwww-perl/HTTP-Message#206 · コメント 1 件 · 担当者 1 名 ·
libwww-perl/HTTP-Message の issue をすべて見る
似ている issue
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
convos-chat/convos#977 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
inverse-inc/packetfence#9387 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
linux-test-project/lcov#552 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
szTheory/exifcleaner#383 ·
メンテナーはふだん 1 日以内に返信
-
1.severity: security
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
NixOS/nixpkgs#569828 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信