react / react/react-native

Commas in cookie value not parsed correctly on Android

未关闭
#29,916 12 条评论 7 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

Needs: Triage :mag: Never gets stale Platform: Android Platform: Linux
主要语言
C++
星标
127k
派生
25.3k
平均合并
1 天 23 小时
30 天内合并 PR
4

描述

Description

tl;dr Commas are treated as cookie deliminators on Android only

Commas (,) in cookie values are not allowed as part of the cookie specification but they're still allowed on all major browsers and through iOS's networking APIs. However in Android okhttp (specifically okhttp3.JavaNetCookieJar) commas are treated as cookie delimiters in the same way that semicolons are. This behaviour isn't mentioned anywhere and is inconsistent with iOS/Web.

I have found an existing issue on okhttp which suggests the regular CookieJar doesn't have this limitation and should be used instead of JavaNetCookieJar. I can also confirm that removing the comma here fixes the issue. React Native sets the okhttp cookie jar to JavaNetCookieJar here.

I'm working with an external service which I can't control so changing the cookie isn't an option. Because {redirect: "manual"} doesn't work in React Native iOS/Android, it's impossible to override this behaviour if the cookie is set in a 302 response and required for subsequent responses.

React Native version:

System:
    OS: Linux 5.3 Linux Mint 19.1 (Tessa)
    CPU: (4) x64 Intel(R) Core(TM) m3-6Y30 CPU @ 0.90GHz
    Memory: 1.50 GB / 7.67 GB
    Shell: 4.4.20 - /bin/bash
  Binaries:
    Node: 10.15.0 - /usr/local/bin/node
    Yarn: Not Found
    npm: 6.4.1 - /usr/local/bin/npm
    Watchman: Not Found
  SDKs:
    Android SDK:
      Android NDK: 17.2.4988734
  IDEs:
    Android Studio: Not Found
  Languages:
    Java: 11.0.3 - /usr/bin/javac
    Python: 2.7.17 - /usr/bin/python
  npmPackages:
    @react-native-community/cli: Not Found
    react: ~16.11.0 => 16.11.0 
    react-native: github:facebook/react-native#0.63-stable => 0.63.2 
  npmGlobalPackages:

Steps To Reproduce and expected results

If a fetch request is made to a server which responds with the following header:

Set-Cookie: TestCookie=a:hello,b:goodbye

On every platform apart from Android, the following Cookie header is sent in future requests:

Cookie: TestCookie=a:hello,b:goodbye;

but on Android the cookie is parsed incorrectly and the following header is sent (2 cookies):

Cookie: TestCookie=a:hello;b:goodbye=;

Snack, code example, screenshot, or link to a repository:

To easily reproduce this, run this express project https://gist.github.com/uen/f8bbded0fc10fd2d3910d388cd3fea6e and load snack https://snack.expo.io/8y09x_Bc7 on a real Android and iOS device (and web). The Android cookie will not be correct as described above

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 ReactAndroid/src/main/java/com/facebook/react/modules/network/NetworkingModule.java 以及所引用的 okhttp3 JavaNetCookieJar.kt 行为开始。运行链接的 Express 项目和 Android 上的 Snack,然后将生成的 Cookie header 与 iOS 和 Web 进行比较。当 Android 上 Cookie 值中的逗号保持不变,或依赖项限制得到明确记录时,即表示完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
android, react-native
领域
mobile, networking
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。