hanicz opened a new pull request, #1429: URL: https://github.com/apache/knox/pull/1429
[KNOX-3488](https://issues.apache.org/jira/browse/KNOX-3488) - harden original-url cookie validation ## What changes were proposed in this pull request? - `WebSSOResource` validated the redirect target only when it came from the `originalUrl` query param — the `original-url`cookie branch used the value verbatim, skipping the userinfo and whitelist checks. A request carrying a crafted cookie was redirected to any attacker host, bypassing the configured (and default) whitelist. ## How was this patch tested? Tested locally, new unit tests, homepage login ``` curl -iku guest:guest-password --cookie "original-url=https://draco.malfoy" 'https://localhost:8443/gateway/knoxsso/api/v1/websso' HTTP/1.1 400 Bad Request curl -iku guest:guest-password --cookie "original-url=https://localhost:[email protected]" 'https://localhost:8443/gateway/knoxsso/api/v1/websso' HTTP/1.1 400 Bad Request curl -iku guest:guest-password --cookie "original-url=https://localhost:8443%[email protected]" 'https://localhost:8443/gateway/knoxsso/api/v1/websso' HTTP/1.1 400 Bad Request curl -iku guest:guest-password 'https://localhost:8443/gateway/knoxsso/api/v1/websso?originalUrl=https://localhost:8443%[email protected]/' HTTP/1.1 400 Bad Request ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
