99designs / 99designs/httpsignatures-go

Missing `Host` header causes signature mismatch

Abierto
#10 0 comentarios 1 reacción 0 asignados Ver en GitHub
Lenguaje dominante
Go
Estrellas
28
Forks
15
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

The 7th draft of the "Signing HTTP Messages" spec [recommends](https://tools.ietf.org/html/draft-cavage-http-signatures-07#appendix-C.2) the use of the `Host` header when calculating a signature.
However, it looks like `Request` from `net/http` removes `Host` from the headers and instead makes it available on the `Request` structure itself.

Example:
```
&http.Request{
Method:"GET",
URL:(*url.URL)(0xc42010d100),
Proto:"HTTP/1.1",
ProtoMajor:1,
ProtoMinor:1,
Header:http.Header{
"Date":[]string{"Tue, 03 Oct 2017 23:18:06 GMT"},
"Accept-Encoding":[]string{"gzip;q=1.0,deflate;q=0.6,identity;q=0.3"},
"Signature":[]string{"keyId=\"key1\",algorithm=\"hmac-sha256\",headers=\"(request-target) host date\",signature=\"T09YOpz+vN+VltcLRok8NgZSVSgm4W6EhjRUNwX7JXQ=\""},
"Connection":[]string{"keep-alive"},
"Keep-Alive":[]string{"30"},
"Accept":[]string{"application/x-msgpack"},
"User-Agent":[]string{"The Client"}
},
Body:http.noBody{},
GetBody:(func() (io.ReadCloser, error))(nil),
ContentLength:0,
TransferEncoding:[]string(nil),
Close:false,
Host:"localhost:3500",
Form:url.Values(nil),
PostForm:url.Values(nil),
MultipartForm:(*multipart.Form)(nil),
Trailer:http.Header(nil),
RemoteAddr:"[::1]:53522",
RequestURI:"/v1/files?ids%5B%5D=1",
TLS:(*tls.ConnectionState)(nil),
Cancel:(<-chan struct {})(nil),
Response:(*http.Response)(nil),
ctx:(*context.cancelCtx)(0xc4201ff8c0)
}
```
Should the `Host` header be special-cased?

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.