Mask a target URL's query string when the URL has no path (closes #500)
check / check (push) Successful in 5m57s
check / check (push) Successful in 5m57s
`urlSecrets` treated a target URL's request URI as a secret only when the URL had a path, so for a target URL such as `https://example.com/?token=…` a response echoing the request line showed the token in the event log and on the event's page. It now also treats the query string, and the request URI that carries it, as secrets whenever the URL has one, whatever its path. With "Pass the query string on to this target" on, only the target's own part is masked, not the event's. A URL with a path is masked as before. As for paths and userinfo, no length floor applies. Model: opus-5-5
This commit was merged in pull request #502.
This commit is contained in:
@@ -162,18 +162,22 @@ func targetSecrets(t *database.Target) []string {
|
||||
}
|
||||
|
||||
// urlSecrets returns the substrings of a destination URL that
|
||||
// must not survive into a rendered page: the whole URL, the
|
||||
// parts of it MaskURL elides, and any userinfo.
|
||||
// must not survive into a rendered page: the whole URL; its
|
||||
// path, unless that is empty or "/"; its query string, and the
|
||||
// request URI that carries it, which a remote echoing the
|
||||
// request line shows even when the URL has no path; and its
|
||||
// userinfo and password.
|
||||
//
|
||||
// No length floor is applied to the path, and none to the
|
||||
// userinfo. A short path or a four-byte username is treated as
|
||||
// a credential exactly like a long one, because the field takes
|
||||
// an arbitrary URL and no part of it can be assumed non-secret —
|
||||
// the same rule MaskURL applies. headerSecrets does carry a
|
||||
// floor, and the difference is deliberate: a header is picked
|
||||
// out by a name-shaped guess and its value may be ordinary
|
||||
// text, whereas a URL's path and userinfo are credential
|
||||
// material by position.
|
||||
// No length floor is applied to the path, the query string or
|
||||
// the userinfo. A short path or a four-byte username is
|
||||
// treated as a credential exactly like a long one, because the
|
||||
// field takes an arbitrary URL and no part of it can be
|
||||
// assumed non-secret — the same rule MaskURL applies.
|
||||
// headerSecrets does carry a floor, and the difference is
|
||||
// deliberate: a header is picked out by a name-shaped guess
|
||||
// and its value may be ordinary text, whereas a URL's path,
|
||||
// query string and userinfo are credential material by
|
||||
// position.
|
||||
func urlSecrets(raw string) []string {
|
||||
raw = strings.TrimSpace(raw)
|
||||
if raw == "" {
|
||||
@@ -188,12 +192,11 @@ func urlSecrets(raw string) []string {
|
||||
}
|
||||
|
||||
if parsed.Path != "" && parsed.Path != "/" {
|
||||
requestURI := parsed.RequestURI()
|
||||
secrets = append(secrets, requestURI)
|
||||
secrets = append(secrets, parsed.EscapedPath())
|
||||
}
|
||||
|
||||
if escaped := parsed.EscapedPath(); escaped != requestURI {
|
||||
secrets = append(secrets, escaped)
|
||||
}
|
||||
if parsed.RawQuery != "" {
|
||||
secrets = append(secrets, parsed.RequestURI(), parsed.RawQuery)
|
||||
}
|
||||
|
||||
if parsed.User != nil {
|
||||
|
||||
Reference in New Issue
Block a user