Skip to content

Commit

Permalink
fix(http): Allow relative redirect on https (#395)
Browse files Browse the repository at this point in the history
Location header can now be relative: https://httpwg.org/specs/rfc9110.html#field.location
  • Loading branch information
nheir authored Oct 8, 2022
1 parent 26b524e commit 8c2ff72
Show file tree
Hide file tree
Showing 2 changed files with 34 additions and 2 deletions.
5 changes: 3 additions & 2 deletions src/http.lua
Original file line number Diff line number Diff line change
Expand Up @@ -300,6 +300,8 @@ local function shouldredirect(reqt, code, headers)
if not location then return false end
location = string.gsub(location, "%s", "")
if location == "" then return false end
-- the RFC says the redirect URL may be relative
location = url.absolute(reqt.url, location)
local scheme = url.parse(location).scheme
if scheme and (not SCHEMES[scheme]) then return false end
-- avoid https downgrades
Expand All @@ -323,8 +325,7 @@ end
local trequest, tredirect

--[[local]] function tredirect(reqt, location)
-- the RFC says the redirect URL has to be absolute, but some
-- servers do not respect that
-- the RFC says the redirect URL may be relative
local newurl = url.absolute(reqt.url, location)
-- if switching schemes, reset port and create function
if url.parse(newurl).scheme ~= reqt.scheme then
Expand Down
31 changes: 31 additions & 0 deletions test/httptest.lua
Original file line number Diff line number Diff line change
Expand Up @@ -265,6 +265,37 @@ ignore = {
}
check_request(request, expect, ignore)

-- Use https://httpbin.org/#/Dynamic_data/get_base64__value_ for testing
-----------------------------------------------------
io.write("testing absolute https redirection: ")
request = {
url = "https://httpbin.org/redirect-to?url=https://httpbin.org/base64/THVhIFNvY2tldA=="
}
expect = {
code = 200,
body = "Lua Socket"
}
ignore = {
status = 1,
headers = 1
}
check_request(request, expect, ignore)

-----------------------------------------------------
io.write("testing relative https redirection: ")
request = {
url = "https://httpbin.org/redirect-to?url=/base64/THVhIFNvY2tldA=="
}
expect = {
code = 200,
body = "Lua Socket"
}
ignore = {
status = 1,
headers = 1
}
check_request(request, expect, ignore)

------------------------------------------------------------------------
--[[
io.write("testing proxy with redirection: ")
Expand Down

0 comments on commit 8c2ff72

Please # to comment.