googleapis / googleapis/google-http-java-client

Core: Authorization and Cookie headers leaked to cross-origin servers on HTTP redirect

Aberta
#2,181 0 comentários 0 reações 0 responsáveis Ver no GitHub
Linguagem predominante
Java
Estrelas
1.4k
Forks
473
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

Environment details
1. Core - HttpRequest in google-http-client
2. OS type and version: Any
3. Java version: Any (Java 8+)
4. google-http-client version: reproducible on current main

Problem Statement
When HttpRequest follows a redirect to a different origin (different scheme, host, or port),
the Cookie header is not stripped. Additionally, Authorization headers set via interceptors
(e.g. BasicAuthentication) are re-applied by the interceptor on subsequent redirect
iterations regardless of destination origin. This can cause credentials to be silently
forwarded to attacker-controlled servers.

Steps to reproduce
1. Build an HttpRequest with an Authorization interceptor (e.g. BasicAuthentication) and a
Cookie header.
2. Configure the transport to return a 302 redirect to a cross-origin URL (different host).
3. Execute the request.
4. Observe that the second request (to the cross-origin target) still includes Authorization
and Cookie headers.

Proposed Fix
In handleRedirect(), compute whether the new URL is same-origin as the old URL (comparing
scheme, host, and effective port). Strip Cookie header if cross-origin. In execute(), before
each retry, compare current URL origin to original origin and strip Authorization and Cookie
if the URL has changed to a different origin (e.g. after a previous redirect).

Add getEffectivePort() and isSameOrigin() helpers to normalize default ports (80 for http,
443 for https).

Three regression tests are included in the accompanying PR covering same-origin,
cross-origin host change, scheme change, and port change scenarios.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Comece em HttpRequest.handleRedirect() e execute(), depois revise os três cenários de regressão descritos na issue. Verifique o comportamento same-origin em alterações de esquema, host e porta, incluindo a normalização da porta padrão; está concluído quando os redirecionamentos cross-origin não contêm os cabeçalhos Authorization e Cookie, enquanto os redirecionamentos same-origin mantêm o comportamento esperado.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
java
Domínio
backend-api-design, security
Tipo de issue
Bug
Dificuldade
3/5
Tempo estimado
1-2 dias
Status de atividade
Pouca atividade
Clareza
Claramente especificada
Facilidade para iniciantes
72/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.