keep method and digest-uri in A2 for qop=auth-int#2269
Open
madib06ops wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Realm.Builder.ha2 writes A2 into the recycled StringBuilder that newResponse took from StringBuilderPool, but on the auth-int branch with no precomputed entity-body hash it calls toHexString, which takes that same thread-local builder and resets it, so the "POST:/secret:" already written is discarded. A2 comes out as the empty-body hash twice and the Digest response no longer binds the request method or the target URI. A server reaches this by answering with qop="auth-int" in WWW-Authenticate or Proxy-Authenticate, since parseRawQop picks auth-int when that is the only value offered.
Appending with appendBase16 keeps the hash in the buffer already being built, which is what newResponse does for HA1 and HA2 a few lines below. The added RealmTest case checks the response against the RFC 7616 A2 and fails on the current code.