googleapis / googleapis/google-http-java-client
Core: Authorization and Cookie headers leaked to cross-origin servers on HTTP redirect
- Lingua principale
- Java
- Stelle
- 1.4k
- Fork
- 473
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
Environment details
1. Core - HttpRequest in google-http-client
2. OS type and version: Any
3. Java version: Any (Java 8+)
4. google-http-client version: reproducible on current main
Problem Statement
When HttpRequest follows a redirect to a different origin (different scheme, host, or port),
the Cookie header is not stripped. Additionally, Authorization headers set via interceptors
(e.g. BasicAuthentication) are re-applied by the interceptor on subsequent redirect
iterations regardless of destination origin. This can cause credentials to be silently
forwarded to attacker-controlled servers.
Steps to reproduce
1. Build an HttpRequest with an Authorization interceptor (e.g. BasicAuthentication) and a
Cookie header.
2. Configure the transport to return a 302 redirect to a cross-origin URL (different host).
3. Execute the request.
4. Observe that the second request (to the cross-origin target) still includes Authorization
and Cookie headers.
Proposed Fix
In handleRedirect(), compute whether the new URL is same-origin as the old URL (comparing
scheme, host, and effective port). Strip Cookie header if cross-origin. In execute(), before
each retry, compare current URL origin to original origin and strip Authorization and Cookie
if the URL has changed to a different origin (e.g. after a previous redirect).
Add getEffectivePort() and isSameOrigin() helpers to normalize default ports (80 for http,
443 for https).
Three regression tests are included in the accompanying PR covering same-origin,
cross-origin host change, scheme change, and port change scenarios.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start in HttpRequest.handleRedirect() and execute(), then review the three regression scenarios described in the issue. Verify same-origin behavior across scheme, host, and port changes, including default-port normalization; done when cross-origin Authorization and Cookie headers are absent while same-origin redirects retain expected behavior.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- java
- Ambito
- backend-api-design, security
- Tipo di issue
- Bug
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Stato di attività
- Tranquilla
- Chiarezza
- Specificata chiaramente
- Idoneità per principianti
- 72/100