Invalid cookie headers being returned
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- perl
- Lĩnh vực
- networking
Hướng nghiên cứu
Bắt đầu bằng cách chạy test case Perl/Plack được cung cấp và kiểm tra cách các header phản hồi được ghép lại thông qua HTTP::Message và HTTP::Headers::Fast. Xác nhận cách nhiều giá trị Set-Cookie được biểu diễn và gộp lại. Hoàn tất có nghĩa là các giá trị Set-Cookie vẫn được giữ riêng biệt và việc xử lý cookie trùng lặp khớp với các đặc tả cookie được trích dẫn.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Hi there,
I think this might belong against HTTP::Headers::Fast, but it's popping up in a client's Plack stack, so I thought I would start here first. This is a small test case:
#!/usr/bin/env perl
use Test::Most;
use Plack::Response;
use Plack::Test;
my $response = Plack::Response->new(200);
$response->content('Hello World');
$response->cookies->{foo} = {
value => 'test',
expires => time + 24 * 60 * 60,
secure => 1,
};
$response->cookies->{bar} = {
value => 'test2',
expires => time + 24 * 60 * 60,
secure => 1,
};
$response->headers->push_header( 'Set-Cookie', 'foo=that' );
# traditional - named params
test_psgi
app => $response->to_app,
client => sub {
my $cb = shift;
my $req = HTTP::Request->new( GET => "http://localhost/hello" );
my $res = $cb->($req);
like $res->content, qr/Hello World/;
explain scalar $res->headers->header('Set-Cookie');
};
done_testing;
That final line prints:
foo=that, bar=test2; expires=Wed, 06-Jul-2022 12:27:13 GMT; secure, foo=test; expires=Wed, 06-Jul-2022 12:27:13 GMT; secure
Per the IETF spec, we have a couple of violations:
Origin servers SHOULD NOT fold multiple Set-Cookie header fields into a single header field. The usual mechanism for folding HTTP headers fields (i.e., as defined in [RFC2616]) might change the semantics of the Set-Cookie header field because the %x2C (",") character is used by Set-Cookie in a way that conflicts with such folding.
As a consequence of the above, in the last sentence of section 4.1.2, we find the following:
User agents ignore unrecognized cookie attributes (but not the entire cookie).
Because the header fields are joined on a comma, we have an invalid secure, attribute, which suggests that strict cookie parsers might accept the cookie, but ignore the strict attribute. This might be a serious security concern.
Servers SHOULD NOT include more than one Set-Cookie header field in the same response with the same cookie-name. (See Section 5.2 for how user agents handle this case.)
In the above example, we have the cookie foo being set twice, with different values and attributes. This caused a serious authentication issue in our client's code.
Admittedly, this code is being used extensively and I'm unsure about a decent approach to solving it.
- Ngôn ngữ chính
- Perl
- Star
- 32
- Fork
- 63
- Merge trung bình
- 5 giờ 14 phút
- Pull request đã merge (30 ngày)
- 1
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của libwww-perl/HTTP-Message
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
libwww-perl/HTTP-Message#228 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
libwww-perl/HTTP-Message#227 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 42/100
libwww-perl/HTTP-Message#216 ·
-
Please add a security policyĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 35/100
libwww-perl/HTTP-Message#207 · 1 bình luận ·
-
Decoding of deflate content-encoding doesn't respect max_body_sizeCó thể đã có người làm @simbabque đã nhận 523 ngày trước. Đang mở
libwww-perl/HTTP-Message#206 · 1 bình luận · 1 người được giao ·
Tất cả issue của libwww-perl/HTTP-Message
Issue tương tự
-
Perl/Fish oddness in new versionĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
gugod/App-perlbrew#879 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
RotherOSS/otobo#6205 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Add IO::Pipe classĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
yuki-kimoto/SPVM-IO#30 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
fglock/PerlOnJava#1651 ·
Maintainer thường phản hồi trong vòng 1 ngày