google / google/go-github

WithAuthToken authorizes requests outside configured hosts

Aperta
#4,366 6 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Go
Stelle
11.3k
Fork
2.5k
Merge medio
1g 22h
PR unite (30g)
49

Descrizione

## Summary

`WithAuthToken` installs a transport wrapper that adds `Authorization: Bearer ` to outgoing requests. When callers build a request with an absolute URL outside the client's configured API or upload origins, that wrapper still adds the bearer token before sending the request.

## Expected behavior

The token configured through `WithAuthToken` should only be attached to requests targeting the client's configured API or upload origins. Requests to other origins should be sent without this transport-managed authorization header.

## Reproduction

This can be reproduced with `httptest` servers by configuring a client with trusted API/upload URLs, then issuing requests using absolute URLs for another server and checking whether that server receives an `Authorization` header.

## Proposed fix

PR #4363 limits token injection to the configured API and upload origins, and includes regression coverage for trusted API/upload requests and cross-host absolute URL requests.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start with the WithAuthToken transport wrapper and the request path it uses for absolute URLs. Reproduce the behavior with httptest servers configured for trusted API/upload origins and a separate origin, then verify trusted requests retain authorization while cross-host requests do not. PR #4363 and its regression coverage describe work already proposed.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
go
Ambito
api, security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Ferma
Chiarezza
Specificata chiaramente
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.