git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http: match headers case-insensitively when redacting

From
Jeff King <peff@peff.net>
Date
Sep 21, 2021, 18:47 UTC
Message-ID
<YUoorS6UwA1DmwBm@coredump.intra.peff.net>
In-Reply-To
<YUonS1uoZlZEt+Yd@coredump.intra.peff.net>
On Tue, Sep 21, 2021 at 02:41:16PM -0400, Jeff King wrote:
Show 18 quoted lines
> When HTTP/2 is in use, we fail to correctly redact "Authorization" (and
> other) headers in our GIT_TRACE_CURL output.
> 
> We get the headers in our CURLOPT_DEBUGFUNCTION callback, curl_trace().
> It passes them along to curl_dump_header(), which in turn checks
> redact_sensitive_header(). We see the headers as a text buffer like:
> 
>   Host: ...
>   Authorization: Basic ...
> 
> After breaking it into lines, we match each header using skip_prefix().
> This is case-insensitive, even though HTTP headers are case-insensitive.
> This has worked reliably in the past because these headers are generated
> by curl itself, which is predictable in what it sends.
> 
> But when HTTP/2 is in use, instead we get a lower-case "authorization:"
> header, and we fail to match it. The fix is simple: we should match with
> skip_iprefix().
Daniel,

I cc'd you here mostly as an FYI. I think Git was doing the wrong thing in assuming case here (we're only expecting these particular headers coming from the client, but for response headers, I thnk curl will give us whatever form the server sent us).

But certainly I found the behavior surprising. :) I'd guess it's because HTTP/2 is sending some binary goo instead of text headers, and the names we get are just coming from some lookup table? Or maybe I'm just showing my ignorance of HTTP/2.

At any rate, I wonder if it would be friendlier for curl to hand strings to the debug function with the usual capitalization.

-Peff
PS This nit aside, it is totally cool that I have been seamlessly using
   HTTP/2 to talk to github.com without even realizing it. I wonder for
   how long!
Previous: Jeff KingNext: Carlo Arenas
Message 2 of 22 in “http: match headers case-insensitively when redacting”
  1. http: match headers case-insensitively when redactingJeff King, Sep 21, 2021
  2. Jeff KingSep 21, 2021
  3. Carlo ArenasSep 21, 2021
  4. Jeff KingSep 21, 2021
  5. Daniel StenbergSep 21, 2021
  6. Jeff KingSep 22, 2021
  7. Eric SunshineSep 21, 2021
  8. Jeff KingSep 21, 2021
  9. Junio C HamanoSep 22, 2021
  10. Taylor BlauSep 21, 2021
  11. Jeff KingSep 22, 2021
  12. Bagas SanjayaSep 22, 2021
  13. Jeff KingSep 22, 2021
  14. Ævar Arnfjörð BjarmasonSep 23, 2021
  15. Jeff KingSep 23, 2021
  16. Junio C HamanoSep 22, 2021
  17. Jeff KingSep 22, 2021
  18. Junio C HamanoSep 22, 2021
  19. Jeff KingSep 22, 2021
  20. Junio C HamanoSep 22, 2021
  21. http: match headers case-insensitively when redactingJeff King, Sep 22, 2021
  22. Jeff KingSep 22, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.