WithAuthToken authorizes requests outside configured hosts
- Lingua principale
- Go
- Stelle
- 11.3k
- Fork
- 2.5k
- Merge medio
- 1g 22h
- PR unite (30g)
- 49
Descrizione
## Summary
`WithAuthToken` installs a transport wrapper that adds `Authorization: Bearer ` to outgoing requests. When callers build a request with an absolute URL outside the client's configured API or upload origins, that wrapper still adds the bearer token before sending the request.
## Expected behavior
The token configured through `WithAuthToken` should only be attached to requests targeting the client's configured API or upload origins. Requests to other origins should be sent without this transport-managed authorization header.
## Reproduction
This can be reproduced with `httptest` servers by configuring a client with trusted API/upload URLs, then issuing requests using absolute URLs for another server and checking whether that server receives an `Authorization` header.
## Proposed fix
PR #4363 limits token injection to the configured API and upload origins, and includes regression coverage for trusted API/upload requests and cross-host absolute URL requests.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start with the WithAuthToken transport wrapper and the request path it uses for absolute URLs. Reproduce the behavior with httptest servers configured for trusted API/upload origins and a separate origin, then verify trusted requests retain authorization while cross-host requests do not. PR #4363 and its regression coverage describe work already proposed.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- go
- Ambito
- api, security
- Tipo di issue
- Bug
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Stato di attività
- Ferma
- Chiarezza
- Specificata chiaramente
- Idoneità per principianti
- 25/100