Andrea Cosentino created CAMEL-24452:
----------------------------------------
Summary: camel-http - credentials are sent to redirect targets on
a different host
Key: CAMEL-24452
URL: https://issues.apache.org/jira/browse/CAMEL-24452
Project: Camel
Issue Type: Bug
Components: camel-http
Reporter: Andrea Cosentino
Assignee: Andrea Cosentino
Fix For: 4.23.0
Two independent paths send credentials to a host the endpoint was never
configured with, once {{followRedirects=true}}:
1. {{OAuth2ClientConfigurer.configureHttpClient}} registers a request
interceptor with {{addRequestInterceptorFirst}} that sets {{Authorization:
Bearer <token>}} unconditionally. HttpClient 5 runs protocol-level request
interceptors inside {{ProtocolExec}}, which sits below {{RedirectExec}} in the
exec chain, so the interceptor runs again for each redirect hop and re-attaches
the token to whatever host the {{Location}} header named. Nothing compares the
request target with the endpoint's configured host, and HC5's cross-site
auth-state reset does not apply because the header is set directly rather than
through the auth exchange.
2. {{HttpCredentialsHelper.getCredentialsProvider}} calls {{setCredentials(new
AuthScope(host, port), credentials)}} with the endpoint's {{authHost}}, which
is optional and null in the common basic-auth setup - {{new AuthScope(null,
-1)}} matches any host, any port, any scheme. HttpClient then offers those
credentials to whichever host issues a 401 Basic challenge.
Proposal: for the OAuth2 interceptor, compare the request's host against the
endpoint's configured host and skip the header when they differ (or move the
token onto the exec chain above {{RedirectExec}}). For basic auth, default the
{{AuthScope}} host to the endpoint's host when {{authHost}} is not set.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)