From 5afbb3fd6d069d87346e85aae13502a5aecbe878 Mon Sep 17 00:00:00 2001 From: Areg Harutyunyan Date: Tue, 6 Aug 2019 16:35:41 -0500 Subject: [PATCH] Revert "TUN-1736: Missing headers when passing an invalid path" This reverts commit 3c93d9b300de99c6906ce8799971fa347cf684e6. --- streamhandler/request.go | 11 ++++- streamhandler/request_test.go | 77 ----------------------------------- 2 files changed, 10 insertions(+), 78 deletions(-) delete mode 100644 streamhandler/request_test.go diff --git a/streamhandler/request.go b/streamhandler/request.go index 05c1bab6..40791d06 100644 --- a/streamhandler/request.go +++ b/streamhandler/request.go @@ -45,7 +45,16 @@ func H2RequestHeadersToH1Request(h2 []h2mux.Header, h1 *http.Request) error { // Otherwise the host header will be based on the origin URL h1.Host = header.Value case ":path": - h1.URL.Path = header.Value + u, err := url.Parse(header.Value) + if err != nil { + return fmt.Errorf("unparseable path") + } + resolved := h1.URL.ResolveReference(u) + // prevent escaping base URL + if !strings.HasPrefix(resolved.String(), h1.URL.String()) { + return fmt.Errorf("invalid path") + } + h1.URL = resolved case "content-length": contentLength, err := strconv.ParseInt(header.Value, 10, 64) if err != nil { diff --git a/streamhandler/request_test.go b/streamhandler/request_test.go deleted file mode 100644 index 68e88282..00000000 --- a/streamhandler/request_test.go +++ /dev/null @@ -1,77 +0,0 @@ -package streamhandler - -import ( - "net/http" - "testing" - - "github.com/cloudflare/cloudflared/h2mux" - - "github.com/stretchr/testify/assert" -) - -func TestH2RequestHeadersToH1Request_RegularHeaders(t *testing.T) { - request, err := http.NewRequest(http.MethodGet, "http://example.com", nil) - assert.NoError(t, err) - - headersConversionErr := H2RequestHeadersToH1Request( - []h2mux.Header{ - h2mux.Header{ - Name: "Mock header 1", - Value: "Mock value 1", - }, - h2mux.Header{ - Name: "Mock header 2", - Value: "Mock value 2", - }, - }, - request, - ) - - assert.Equal(t, http.Header{ - "Mock header 1": []string{"Mock value 1"}, - "Mock header 2": []string{"Mock value 2"}, - }, request.Header) - - assert.NoError(t, headersConversionErr) -} - -func TestH2RequestHeadersToH1Request_NoHeaders(t *testing.T) { - request, err := http.NewRequest(http.MethodGet, "http://example.com", nil) - assert.NoError(t, err) - - headersConversionErr := H2RequestHeadersToH1Request( - []h2mux.Header{}, - request, - ) - - assert.Equal(t, http.Header{}, request.Header) - - assert.NoError(t, headersConversionErr) -} - -func TestH2RequestHeadersToH1Request_InvalidHostPath(t *testing.T) { - request, err := http.NewRequest(http.MethodGet, "http://example.com", nil) - assert.NoError(t, err) - - headersConversionErr := H2RequestHeadersToH1Request( - []h2mux.Header{ - h2mux.Header{ - Name: ":path", - Value: "//bad_path/", - }, - h2mux.Header{ - Name: "Mock header", - Value: "Mock value", - }, - }, - request, - ) - - assert.Equal(t, http.Header{ - "Mock header": []string{"Mock value"}, - }, request.Header) - - assert.Equal(t, request.URL.String(), "http://example.com//bad_path/") - - assert.NoError(t, headersConversionErr) -}