[ 
https://issues.apache.org/jira/browse/HTTPCLIENT-2372?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17956313#comment-17956313
 ] 

Michael Osipov commented on HTTPCLIENT-2372:
--------------------------------------------

A protocol upgrade should be safe, but not a downgrade.

> Redirection to same target with sensitive headers is not followed
> -----------------------------------------------------------------
>
>                 Key: HTTPCLIENT-2372
>                 URL: https://issues.apache.org/jira/browse/HTTPCLIENT-2372
>             Project: HttpComponents HttpClient
>          Issue Type: Bug
>    Affects Versions: 5.5
>            Reporter: Jonathan Yan
>            Priority: Minor
>             Fix For: 5.5.1
>
>         Attachments: Issue.java
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> When redirecting to the same target, e.g., [https://news.google.com/] gets 
> redirected to [https://news.google.com/home?hl=en-GB&gl=GB&ceid=GB:en], even 
> if there is some sensitive header, the {{HttpClient}} should still 
> automatically follow the redirect (when it is enabled).
> The issue seems to be that in 
> {{{}DefaultRedirectStrategy.isRedirectAllowed(...){}}}, the {{currentTarget}} 
> (https://news.google.com:443) has an explicit port while the {{newTarget}} 
> (https://news.google.com) doesn't and are considered not matching.
> The issue can be reproduced with the attached file using 
> {{{}org.apache.httpcomponents.client5:httpclient5:5.5{}}}.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@hc.apache.org
For additional commands, e-mail: dev-h...@hc.apache.org

Reply via email to