SoapClient only strips `Authorization: Basic` when a WSDL imports from another host
Mantenedores costumam responder em até 1 dia
Avaliação
Esta issue ainda não foi avaliada.
Descrição
Description
Originally reported by @christos-cantina-security.
When a WSDL imports a schema or another WSDL from a different host, SoapClient clears the credentials from the stream context before fetching it in sdl_set_uri_credentials() @ ext/soap/php_sdl.c. The strip only matches the exact string Authorization: Basic in http.header, and only when that option is a string. The TODO right above it already notes that the array form of http.header is not handled.
Any other credential passes through to the third-party host as-is: a Bearer or Digest Authorization header, a lowercase authorization: header, a Cookie header, a Proxy-Authorization header, and every header given as an array.
The following code, with https://a.example serving a WSDL that contains <xsd:import schemaLocation="https://b.example/schema.xsd"/>:
<?php
$client = new SoapClient('https://a.example/service.wsdl', [
'cache_wsdl' => WSDL_CACHE_NONE,
'stream_context' => stream_context_create([
'http' => ['header' => "Authorization: Bearer secret-token\r\n"],
]),
]);
Resulted in this request on b.example:
GET /schema.xsd HTTP/1.1
Host: b.example
Authorization: Bearer secret-token
But I expected the header to be dropped on the host change, like Authorization: Basic already is:
GET /schema.xsd HTTP/1.1
Host: b.example
This should be hardened on master, potentially introducing a BC break:
- strip every
Authorization,Proxy-AuthorizationandCookieheader, case-insensitively - handle the array form of
http.header, resolving the existingTODO - add a
SoapClientoption to keep the headers for setups where the same credentials serve both hosts - document the behavior change in
UPGRADING
PHP Version
master
Operating System
No response
- Linguagem predominante
- C
- Estrelas
- 40.4k
- Forks
- 8.2k
- Merge médio
- 2d 7h
- PRs com merge (30d)
- 153
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de php/php-src
-
Bug Status: Needs Triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
php/php-src#24121 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Variant analysis: 1 unfixed sibling safety gap in php-srcTalvez já em andamento @kamil-tekiela assumiu há 6 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
php/php-src#23958 · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
sapi_lsapi_ub_write does not return bytes written in lsapi modeTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. AbertaBug Status: Needs Triage
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
Mantenedores costumam responder em até 1 dia
-
Bug Status: Needs Triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
Flaky hrtime.phpt testTalvez já em andamento @veksa assumiu há 61 dias. AbertaBug Category: Tests Status: Verified
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
Mantenedores costumam responder em até 1 dia
Todas as issues de php/php-src
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
Mantenedores costumam responder em até 2 dias
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 86/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 82/100
MixinNetwork/flutter-plugins#512 ·
-
issue: bug report
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
openssl/openssl#33096 · 1 comentário ·
Mantenedores costumam responder em até 2 dias