Skip to content

Require a space after the Basic authentication scheme - #3138

Open
Shubham-Padkonde wants to merge 1 commit into
labstack:masterfrom
Shubham-Padkonde:fix/basic-auth-scheme-boundary
Open

Shubham-Padkonde wants to merge 1 commit into
labstack:masterfrom
Shubham-Padkonde:fix/basic-auth-scheme-boundary

Conversation

@Shubham-Padkonde

Copy link
Copy Markdown

BasicAuth checks the Basic prefix but does not check the following separator. As a result, BasicX followed by valid encoded credentials reaches the protected handler. An unrelated scheme with that prefix can also consume AllowedCheckLimit, preventing a later valid Basic header from being checked.

Require the space after the scheme before decoding or counting a header. Case-insensitive Basic matching and the existing invalid-base64 behavior are unchanged.

Both added regression cases fail before the fix. The complete Linux go test -race ./... suite and go vet ./... pass afterward.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant