Commas in cookie value not parsed correctly on Android
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- C++
- Sterne
- 127k
- Forks
- 25.3k
- Ø Merge
- 1 T. 23 Std.
- Gemergte PRs (30 T.)
- 4
Beschreibung
Description
tl;dr Commas are treated as cookie deliminators on Android only
Commas (,) in cookie values are not allowed as part of the cookie specification but they're still allowed on all major browsers and through iOS's networking APIs. However in Android okhttp (specifically okhttp3.JavaNetCookieJar) commas are treated as cookie delimiters in the same way that semicolons are. This behaviour isn't mentioned anywhere and is inconsistent with iOS/Web.
I have found an existing issue on okhttp which suggests the regular CookieJar doesn't have this limitation and should be used instead of JavaNetCookieJar. I can also confirm that removing the comma here fixes the issue. React Native sets the okhttp cookie jar to JavaNetCookieJar here.
I'm working with an external service which I can't control so changing the cookie isn't an option. Because {redirect: "manual"} doesn't work in React Native iOS/Android, it's impossible to override this behaviour if the cookie is set in a 302 response and required for subsequent responses.
React Native version:
System:
OS: Linux 5.3 Linux Mint 19.1 (Tessa)
CPU: (4) x64 Intel(R) Core(TM) m3-6Y30 CPU @ 0.90GHz
Memory: 1.50 GB / 7.67 GB
Shell: 4.4.20 - /bin/bash
Binaries:
Node: 10.15.0 - /usr/local/bin/node
Yarn: Not Found
npm: 6.4.1 - /usr/local/bin/npm
Watchman: Not Found
SDKs:
Android SDK:
Android NDK: 17.2.4988734
IDEs:
Android Studio: Not Found
Languages:
Java: 11.0.3 - /usr/bin/javac
Python: 2.7.17 - /usr/bin/python
npmPackages:
@react-native-community/cli: Not Found
react: ~16.11.0 => 16.11.0
react-native: github:facebook/react-native#0.63-stable => 0.63.2
npmGlobalPackages:
Steps To Reproduce and expected results
If a fetch request is made to a server which responds with the following header:
Set-Cookie: TestCookie=a:hello,b:goodbye
On every platform apart from Android, the following Cookie header is sent in future requests:
Cookie: TestCookie=a:hello,b:goodbye;
but on Android the cookie is parsed incorrectly and the following header is sent (2 cookies):
Cookie: TestCookie=a:hello;b:goodbye=;
Snack, code example, screenshot, or link to a repository:
To easily reproduce this, run this express project https://gist.github.com/uen/f8bbded0fc10fd2d3910d388cd3fea6e and load snack https://snack.expo.io/8y09x_Bc7 on a real Android and iOS device (and web). The Android cookie will not be correct as described above
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne mit ReactAndroid/src/main/java/com/facebook/react/modules/network/NetworkingModule.java und dem Verhalten von okhttp3 JavaNetCookieJar.kt, auf das verwiesen wird. Führe das verlinkte Express-Projekt und Snack auf Android aus und vergleiche den resultierenden Cookie-Header mit iOS und dem Web. Als erledigt gilt die Aufgabe, wenn Kommas in Cookie-Werten unter Android intakt bleiben oder die Einschränkung der Abhängigkeit eindeutig dokumentiert ist.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- android, react-native
- Bereich
- mobile, networking
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 45/100