php / php/php-src

SoapClient only strips `Authorization: Basic` when a WSDL imports from another host

Abierto
#23,686 10 comentarios 0 reacciones 1 asignado Ver en GitHub

@DanielEScherzer ya está trabajando en esto.

Desde el 15/9/2026.

Bug Status: Needs Triage
Lenguaje dominante
C
Estrellas
40.4k
Forks
8.2k
Merge medio
2 d 13 h
PR fusionados (30 d)
96

Descripción

Description

Originally reported by @christos-cantina-security.

When a WSDL imports a schema or another WSDL from a different host, SoapClient clears the credentials from the stream context before fetching it in sdl_set_uri_credentials() @ ext/soap/php_sdl.c. The strip only matches the exact string Authorization: Basic in http.header, and only when that option is a string. The TODO right above it already notes that the array form of http.header is not handled.

Any other credential passes through to the third-party host as-is: a Bearer or Digest Authorization header, a lowercase authorization: header, a Cookie header, a Proxy-Authorization header, and every header given as an array.

The following code, with https://a.example serving a WSDL that contains <xsd:import schemaLocation="https://b.example/schema.xsd"/>:

<?php
$client = new SoapClient('https://a.example/service.wsdl', [
    'cache_wsdl' => WSDL_CACHE_NONE,
    'stream_context' => stream_context_create([
        'http' => ['header' => "Authorization: Bearer secret-token\r\n"],
    ]),
]);

Resulted in this request on b.example:

GET /schema.xsd HTTP/1.1
Host: b.example
Authorization: Bearer secret-token

But I expected the header to be dropped on the host change, like Authorization: Basic already is:

GET /schema.xsd HTTP/1.1
Host: b.example

This should be hardened on master, potentially introducing a BC break:

  • strip every Authorization, Proxy-Authorization and Cookie header, case-insensitively
  • handle the array form of http.header, resolving the existing TODO
  • add a SoapClient option to keep the headers for setups where the same credentials serve both hosts
  • document the behavior change in UPGRADING
PHP Version
master
Operating System

No response

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.