googleapis / googleapis/google-http-java-client

Core: Authorization and Cookie headers leaked to cross-origin servers on HTTP redirect

Abierto
#2,181 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Java
Estrellas
1.4k
Forks
473
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

Environment details
1. Core - HttpRequest in google-http-client
2. OS type and version: Any
3. Java version: Any (Java 8+)
4. google-http-client version: reproducible on current main

Problem Statement
When HttpRequest follows a redirect to a different origin (different scheme, host, or port),
the Cookie header is not stripped. Additionally, Authorization headers set via interceptors
(e.g. BasicAuthentication) are re-applied by the interceptor on subsequent redirect
iterations regardless of destination origin. This can cause credentials to be silently
forwarded to attacker-controlled servers.

Steps to reproduce
1. Build an HttpRequest with an Authorization interceptor (e.g. BasicAuthentication) and a
Cookie header.
2. Configure the transport to return a 302 redirect to a cross-origin URL (different host).
3. Execute the request.
4. Observe that the second request (to the cross-origin target) still includes Authorization
and Cookie headers.

Proposed Fix
In handleRedirect(), compute whether the new URL is same-origin as the old URL (comparing
scheme, host, and effective port). Strip Cookie header if cross-origin. In execute(), before
each retry, compare current URL origin to original origin and strip Authorization and Cookie
if the URL has changed to a different origin (e.g. after a previous redirect).

Add getEffectivePort() and isSameOrigin() helpers to normalize default ports (80 for http,
443 for https).

Three regression tests are included in the accompanying PR covering same-origin,
cross-origin host change, scheme change, and port change scenarios.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start in HttpRequest.handleRedirect() and execute(), then review the three regression scenarios described in the issue. Verify same-origin behavior across scheme, host, and port changes, including default-port normalization; done when cross-origin Authorization and Cookie headers are absent while same-origin redirects retain expected behavior.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
java
Área
backend-api-design, security
Tipo de issue
Error
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Tranquilo
Claridad
Bien especificado
Aptitud para principiantes
72/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.