Skip to content

Trim whitespace around tokens when parsing an Authorization header - #50

Open
RaphaelFakhri wants to merge 1 commit into
superfly:mainfrom
RaphaelFakhri:fix-parse-token-list-whitespace
Open

RaphaelFakhri wants to merge 1 commit into
superfly:mainfrom
RaphaelFakhri:fix-parse-token-list-whitespace

Conversation

@RaphaelFakhri

Copy link
Copy Markdown

Trim whitespace around each token in Parse so token lists separated by , are accepted.

Problem

Parse splits an Authorization header on , and reads the prefix of each element up to _. HTTP allows optional whitespace around the commas in a list, and proxies that fold repeated header lines join them with , . A header such as FlyV1 fm2_AAAA, fm2_BBBB fails with invalid token prefix ' fm2'. The same happens with a space before the comma, which is decoded as invalid base64.

Fix

Trim whitespace from each element before splitting off the prefix. Headers without extra whitespace parse exactly as before.

Testing

go test . -run TestParseTokenListWhitespace
  • Fails before the change (3 of 5 subtests: comma space, space around comma, comma tab) and passes after.
  • go test ./... and go vet . pass.

Fixes #49

The token list is comma separated, and HTTP allows optional whitespace
around the commas. Proxies that fold repeated headers join values with
", ", which made Parse fail with an invalid token prefix error.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Parse rejects comma-separated tokens that have whitespace after the comma

1 participant