Skip to content

strip userinfo from the absolute-form proxy request target#2258

Open
madib06ops wants to merge 1 commit into
AsyncHttpClient:mainfrom
madib06ops:proxy-request-uri-userinfo
Open

strip userinfo from the absolute-form proxy request target#2258
madib06ops wants to merge 1 commit into
AsyncHttpClient:mainfrom
madib06ops:proxy-request-uri-userinfo

Conversation

@madib06ops

Copy link
Copy Markdown
Contributor

When a plaintext request goes through an HTTP proxy, requestUri() builds the absolute-form request target with Uri.toUrl(), which embeds the userinfo, so a request for http://user:secret@origin.example.com/resource sends those credentials to the proxy in the clear on the request line and into its access log. RFC 9110 section 4.2.4 says a sender must not generate the userinfo subcomponent when a request target is built. The sibling paths already comply: CONNECT uses getAuthority(), the Host header comes from hostHeader(uri), and the HTTP/2 path runs stripUserInfo() before setting :authority, so only the HTTP/1.1 absolute-form branch was missed. Kept toUrl() and the caller-visible Request.getUrl() unchanged and added a variant that omits the userinfo, with a test that fails on the current request line.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant