Cookie parsing does not adhere to RFC (concerning multiple values with the same key)
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 45/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- rust
- Lĩnh vực
- documentation
Hướng nghiên cứu
Review src/common/cookie.rs, especially Cookie::get, alongside RFC 6265 section 4.2.2. Determine where its behavior is documented and update that documentation to explain handling of duplicate cookie names and the ordering caveat; done means the behavior and its security implications are clear to users.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
According to to the quoted RFC 6265, section 4.2.2
Although cookies are serialized linearly in the Cookie header,
servers SHOULD NOT rely upon the serialization order. In particular,
if the Cookie header contains two cookies with the same name (e.g.,
that were set with different Path or Domain attributes), servers
SHOULD NOT rely upon the order in which these cookies appear in the
header.
The relevant function Cookie::get does not comply with that:
https://github.com/hyperium/headers/blob/ffca4a90482cc31875ac9a9364b7ea252f8c0afa/src/common/cookie.rs#L45-L49
Instead, it only takes the first cookie value of a certain name.
The documentation should call this out, especially if this is not a de-facto standard somewhere because then it can create security vulnerabilities with different parts of a web stack taking different (first, last) values of a cookie with a certain name as authoritative.
- Ngôn ngữ chính
- Rust
- Star
- 200
- Fork
- 108
- Merge trung bình
- 3 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 2
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của hyperium/headers
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
-
Range::bytes and ContentRange::bytes do unchecked u64 arithmetic on boundsCó thể đã có người làm @youdie006 đã nhận 58 ngày trước. Đang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 78/100
-
From<SystemTime> for HttpDate panics on times before 1970 or after year 9999Có thể đã có người làm @SAY-5 đã nhận 77 ngày trước. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
-
Link supportĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
Tất cả issue của hyperium/headers
Issue tương tự
-
[Bug]: Web chat input doesn't regain focus after a reply finishesCó thể đã có người làm @GaijinSystems đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
zeroclaw-labs/zeroclaw#11658 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
good first issue help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
NuSkooler/enigma-bbs#907 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày