[ https://issues.apache.org/jira/browse/HTTPCLIENT-2203?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Oleg Kalnichevski updated HTTPCLIENT-2203: ------------------------------------------ Fix Version/s: 5.1.4 5.2-alpha2 > Credentials not sent when using preemptive auth > ----------------------------------------------- > > Key: HTTPCLIENT-2203 > URL: https://issues.apache.org/jira/browse/HTTPCLIENT-2203 > Project: HttpComponents HttpClient > Issue Type: Bug > Affects Versions: 5.1.1, 5.1.2, 5.1.3 > Reporter: S Howlett > Priority: Major > Fix For: 5.1.4, 5.2-alpha2 > > > After version 5.0.3, preemptive auth appears to be broken, with the > {{Authorization}} header missing from requests sent. I wonder if this may be > related to the fix for HTTPCLIENT-2147. > I was able to reproduce this problem using the [Preemptive Authentication > example|https://github.com/apache/httpcomponents-client/blob/5.1.x/httpclient5/src/test/java/org/apache/hc/client5/http/examples/ClientPreemptiveBasicAuthentication.java] > provided in the > [httpcomponents-client|https://github.com/apache/httpcomponents-client] > GitHub repo. Below I outline the differences between the behaviour of > HttpClient 5.0.3 and 5.1.1+ (using the Preemptive Authentication example, and > Java 15.0.1). Nothing besides the HttpClient version was altered between the > two cases. > h2. *HttpClient 5.0.3* > Preemptive Authentication example works as expected. > Output: > {code:java} > Executing request GET http://httpbin.org/hidden-basic-auth/user/passwd > ---------------------------------------- > 200 OK > { > "authenticated": true, > "user": "user" > } > ---------------------------------------- > 200 OK > { > "authenticated": true, > "user": "user" > } > ---------------------------------------- > 200 OK > { > "authenticated": true, > "user": "user" > } {code} > Debugging showed that, at [RedirectExec.java, line > 118|https://github.com/apache/httpcomponents-client/blob/5.0.x/httpclient5/src/main/java/org/apache/hc/client5/http/impl/classic/RedirectExec.java#L118], > {{currentRequest}} has 5 headers, including the {{Authorization}} header > with Basic credentials. (Frames: RedirectExec.java, execute:118; > ExecChainElement, execute:51; InternalHttpClient, doExecute:178; > ClosableHttpClient, execute:75; ClientPreemptiveBasicAuthentication, main:66) > > h2. *{color:#172b4d}HttpClient 5.1.1{color} and above* > Credentials are not sent with requests in the Preemptive Authentication > example. > Output: > {code:java} > Executing request GET http://httpbin.org/hidden-basic-auth/user/passwd > ---------------------------------------- > 404 NOT FOUND > ---------------------------------------- > 404 NOT FOUND > ---------------------------------------- > 404 NOT FOUND {code} > Note: Not sure why the response is 404 with this URL; it is an authorisation > issue and other URLs tend to return 403. > Debugging showed that, at [RedirectExec.java, line > 117|https://github.com/apache/httpcomponents-client/blob/5.1.x/httpclient5/src/main/java/org/apache/hc/client5/http/impl/classic/RedirectExec.java#L117] > (which is equivalent to line 118 in 5.0.x), {{currentRequest}} has 4 > headers, NOT including the {{Authorization}} header. (Frames: > RedirectExec.java, execute:117; ExecChainElement, execute:51; > InternalHttpClient, doExecute:170; ClosableHttpClient, execute:75; > ClientPreemptiveBasicAuthentication, main:66) -- This message was sent by Atlassian Jira (v8.20.1#820001) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@hc.apache.org For additional commands, e-mail: dev-h...@hc.apache.org