Robustly parse quoted WWW-Authenticate parameters
维护者通常 9 天内回复
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 55/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- csharp
调研方向
定位 ClientOAuthProvider 中 WWW-Authenticate 参数的解析逻辑,并先阅读 RFC 9110 的第 11.6.1 节和参数处理部分。验证引号字符串中的逗号以及 \" 之类的转义引号的行为;当这些值能够被解析且不会破坏响应处理,并且边界情况有测试覆盖时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Something like param="," can break our naive WWW-Authenticate parameter parsing logic in ClientOAuthProvider. While I don't expect many servers will be sending parameters like that in their responses, and it'd be very unusual for an attacker to have only partial control over a WWW-Authenticate response header value, it'd be best to properly account for things like commas inside of quoted strings or escaped quotes. \".
It's a bit like CSV with its quote handling trickiness.
See https://github.com/modelcontextprotocol/csharp-sdk/pull/1084#discussion_r2612746896 for more context.
https://gist.github.com/halter73/aca998c8855b4260b7ae2e705d85ec98 Includes a copilot conversation I had investigating if there was a built-in API we could leverage, and it appears not.
RFC 9110 contains the relevant specs for the WWW-Authenticate header and how to read a parameter.
https://www.rfc-editor.org/rfc/rfc9110#section-11.6.1
https://www.rfc-editor.org/rfc/rfc9110#parameter
- 主要语言
- C#
- 星标
- 4.6k
- 派生
- 819
- 平均合并
- 4 天 23 小时
- 30 天内合并 PR
- 2
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
modelcontextprotocol/csharp-sdk 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 74/100
modelcontextprotocol/csharp-sdk#1913 ·
维护者通常 9 天内回复
-
ClaimsPrincipal parameter injection sample request可能已有人在做 @utsavjain2809 于 6 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 74/100
modelcontextprotocol/csharp-sdk#1899 ·
维护者通常 9 天内回复
-
Document ClientOAuthOptions.ScopeSelector usage可能已有人在做 @z0rimo 于 30 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
modelcontextprotocol/csharp-sdk#1867 · 1 条评论 ·
维护者通常 9 天内回复
-
HTTP+SSE client: POST responses are never disposed, leaking one connection per sent message可能已有人在做 @yalcinfu22 于 44 天前认领。 未关闭
难度 1/5 1 小时以内 新手友好度 88/100
modelcontextprotocol/csharp-sdk#1840 · 1 条评论 ·
维护者通常 9 天内回复
-
stdio client never closes the server's stdin, so every client dispose burns the full ShutdownTimeout (5s by default)可能已有人在做 @luisangelrod 于 45 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 84/100
modelcontextprotocol/csharp-sdk#1836 · 1 条评论 ·
维护者通常 9 天内回复
查看 modelcontextprotocol/csharp-sdk 的全部 Issue
相似的 Issue
-
area:jobads-cv BE mvp P2
难度 2/5 1-3 小时 新手友好度 62/100
klasolsson81/jobbliggaren#2099 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
0 - Backlog Bug
难度 2/5 1-3 小时 新手友好度 62/100
BrighterCommand/Brighter#4581 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 92/100
Esri/calcite-dotnet-toolkit#30 · 1 个 reaction ·
-
kind:docs simplification size:S status:todo
难度 2/5 1-3 小时 新手友好度 82/100
elsa-workflows/elsa-foundation#2604 ·
维护者通常 1 天内回复