Hi,

these two patches fix GitHub issue #3493, which Christopher confirmed.

The normalizers that take an optional sub-option only set rule->action
in the branch handling that sub-option and in the branch handling the
end of the arguments. When the sub-option is left out and an "if" or
"unless" follows the normalizer name directly, neither branch is taken
and rule->action keeps its initial value, which happens to be
ACT_NORMALIZE_URI_PATH_MERGE_SLASHES.

So this configuration:

    http-request normalize-uri percent-decode-unreserved if { ... }

merges duplicate slashes instead of decoding percent sequences.
percent-to-uppercase and path-strip-dotdot are affected the same way;
spelling out "strict" or "full" avoids it.

The first patch sets the default action right after the normalizer name
is matched and lets the sub-option overwrite it, keeping the check that
rejects unknown arguments. The second one adds a reg-test: the request
carries both a percent sequence and duplicate slashes so that the two
candidate normalizers produce different results. With the first patch
reverted it fails on the value, not on a missing header.

The three affected normalizers all landed in 2.4-dev, so this looks
backportable to all stable versions.

Best regards

Youngkwang Lee (2):
  BUG/MEDIUM: http_act: fix normalize-uri normalizer selection with a
    condition
  REGTESTS: uri_normalizer: test a normalizer used with a condition

 reg-tests/http-rules/normalize_uri.vtc | 27 ++++++++++++++++++++++++++
 src/http_act.c                         | 24 +++++++++++------------
 2 files changed, 39 insertions(+), 12 deletions(-)

-- 
2.45.1



Reply via email to