From 0bc5fc8923570bc9e2ef6a0565c4696aee535488 Mon Sep 17 00:00:00 2001 From: Shubham Padkonde Date: Thu, 1 Oct 2026 22:40:25 +0530 Subject: [PATCH] fix: check Basic authentication scheme boundary --- middleware/basic_auth.go | 2 +- middleware/basic_auth_test.go | 15 +++++++++++++++ 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/middleware/basic_auth.go b/middleware/basic_auth.go index 8a9500a93..535ed4156 100644 --- a/middleware/basic_auth.go +++ b/middleware/basic_auth.go @@ -121,7 +121,7 @@ func (config BasicAuthConfig) ToMiddleware() (echo.MiddlewareFunc, error) { if i >= limit { break } - if len(auth) <= l+1 || !strings.EqualFold(auth[:l], basic) { + if len(auth) <= l+1 || auth[l] != ' ' || !strings.EqualFold(auth[:l], basic) { continue } i++ diff --git a/middleware/basic_auth_test.go b/middleware/basic_auth_test.go index 42386354f..0ba18a8d0 100644 --- a/middleware/basic_auth_test.go +++ b/middleware/basic_auth_test.go @@ -56,6 +56,21 @@ func TestBasicAuth(t *testing.T) { basic + " " + base64.StdEncoding.EncodeToString([]byte("joe:secret")), }, }, + { + name: "nok, missing space after scheme", + givenConfig: defaultConfig, + whenAuth: []string{"BasicX" + base64.StdEncoding.EncodeToString([]byte("joe:secret"))}, + expectHeader: basic + ` realm="Restricted"`, + expectErr: "Unauthorized", + }, + { + name: "ok, unrelated scheme does not consume check limit", + givenConfig: defaultConfig, + whenAuth: []string{ + "BasicX" + base64.StdEncoding.EncodeToString([]byte("joe:invalid_password")), + basic + " " + base64.StdEncoding.EncodeToString([]byte("joe:secret")), + }, + }, { name: "nok, multiple, valid out of limit", givenConfig: BasicAuthConfig{Validator: validatorFunc, AllowedCheckLimit: 1},