google / google/go-github

WithAuthToken authorizes requests outside configured hosts

Offen
#4,366 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Go
Sterne
11.3k
Forks
2.5k
Ø Merge
1 T. 20 Std.
Gemergte PRs (30 T.)
52

Beschreibung

## Summary

`WithAuthToken` installs a transport wrapper that adds `Authorization: Bearer ` to outgoing requests. When callers build a request with an absolute URL outside the client's configured API or upload origins, that wrapper still adds the bearer token before sending the request.

## Expected behavior

The token configured through `WithAuthToken` should only be attached to requests targeting the client's configured API or upload origins. Requests to other origins should be sent without this transport-managed authorization header.

## Reproduction

This can be reproduced with `httptest` servers by configuring a client with trusted API/upload URLs, then issuing requests using absolute URLs for another server and checking whether that server receives an `Authorization` header.

## Proposed fix

PR #4363 limits token injection to the configured API and upload origins, and includes regression coverage for trusted API/upload requests and cross-host absolute URL requests.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the WithAuthToken transport wrapper and the request path it uses for absolute URLs. Reproduce the behavior with httptest servers configured for trusted API/upload origins and a separate origin, then verify trusted requests retain authorization while cross-host requests do not. PR #4363 and its regression coverage describe work already proposed.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
go
Bereich
api, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Veraltet
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.