diff --git a/streamhandler/request.go b/streamhandler/request.go index e4bbaaee..40791d06 100644 --- a/streamhandler/request.go +++ b/streamhandler/request.go @@ -45,13 +45,16 @@ func H2RequestHeadersToH1Request(h2 []h2mux.Header, h1 *http.Request) error { // Otherwise the host header will be based on the origin URL h1.Host = header.Value case ":path": - // Separate the path and the (optional) query from each other - chunks := strings.SplitN(header.Value, "?", 2) - - h1.URL.Path = chunks[0] - if len(chunks) > 1 { - h1.URL.RawQuery = chunks[1] + u, err := url.Parse(header.Value) + if err != nil { + return fmt.Errorf("unparseable path") } + resolved := h1.URL.ResolveReference(u) + // prevent escaping base URL + if !strings.HasPrefix(resolved.String(), h1.URL.String()) { + return fmt.Errorf("invalid path") + } + h1.URL = resolved case "content-length": contentLength, err := strconv.ParseInt(header.Value, 10, 64) if err != nil { diff --git a/streamhandler/request_test.go b/streamhandler/request_test.go deleted file mode 100644 index 7e51da90..00000000 --- a/streamhandler/request_test.go +++ /dev/null @@ -1,104 +0,0 @@ -package streamhandler - -import ( - "net/http" - "testing" - - "github.com/cloudflare/cloudflared/h2mux" - - "github.com/stretchr/testify/assert" -) - -func TestH2RequestHeadersToH1Request_RegularHeaders(t *testing.T) { - request, err := http.NewRequest(http.MethodGet, "http://example.com", nil) - assert.NoError(t, err) - - headersConversionErr := H2RequestHeadersToH1Request( - []h2mux.Header{ - h2mux.Header{ - Name: "Mock header 1", - Value: "Mock value 1", - }, - h2mux.Header{ - Name: "Mock header 2", - Value: "Mock value 2", - }, - }, - request, - ) - - assert.Equal(t, http.Header{ - "Mock header 1": []string{"Mock value 1"}, - "Mock header 2": []string{"Mock value 2"}, - }, request.Header) - - assert.NoError(t, headersConversionErr) -} - -func TestH2RequestHeadersToH1Request_NoHeaders(t *testing.T) { - request, err := http.NewRequest(http.MethodGet, "http://example.com", nil) - assert.NoError(t, err) - - headersConversionErr := H2RequestHeadersToH1Request( - []h2mux.Header{}, - request, - ) - - assert.Equal(t, http.Header{}, request.Header) - - assert.NoError(t, headersConversionErr) -} - -func TestH2RequestHeadersToH1Request_InvalidHostPath(t *testing.T) { - request, err := http.NewRequest(http.MethodGet, "http://example.com", nil) - assert.NoError(t, err) - - headersConversionErr := H2RequestHeadersToH1Request( - []h2mux.Header{ - h2mux.Header{ - Name: ":path", - Value: "//bad_path/", - }, - h2mux.Header{ - Name: "Mock header", - Value: "Mock value", - }, - }, - request, - ) - - assert.Equal(t, http.Header{ - "Mock header": []string{"Mock value"}, - }, request.Header) - - assert.Equal(t, "http://example.com//bad_path/", request.URL.String()) - - assert.NoError(t, headersConversionErr) -} - -func TestH2RequestHeadersToH1Request_HostPathWithQuery(t *testing.T) { - request, err := http.NewRequest(http.MethodGet, "http://example.com/", nil) - assert.NoError(t, err) - - headersConversionErr := H2RequestHeadersToH1Request( - []h2mux.Header{ - h2mux.Header{ - Name: ":path", - Value: "/?query", - }, - h2mux.Header{ - Name: "Mock header", - Value: "Mock value", - }, - }, - request, - ) - - assert.Equal(t, http.Header{ - "Mock header": []string{"Mock value"}, - }, request.Header) - - assert.Equal(t, "http://example.com/?query", request.URL.String()) - - assert.NoError(t, headersConversionErr) -}