Changeset 18913 in josm for trunk/src


Ignore:
Timestamp:
2023-12-14T16:31:54+01:00 (12 months ago)
Author:
taylor.smock
Message:

See #22596: Some hosts redirect to another host for authentication (patch by hhtznr, modified)

This lets plugins do authentication with hosts that redirect to another host
for authentication.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/org/openstreetmap/josm/tools/HttpClient.java

    r18801 r18913  
    99import java.net.CookieHandler;
    1010import java.net.CookieManager;
     11import java.net.CookiePolicy;
    1112import java.net.HttpURLConnection;
    1213import java.net.MalformedURLException;
     
    8485    static {
    8586        try {
    86             CookieHandler.setDefault(new CookieManager());
     87            CookieHandler.setDefault(new CookieManager(null, CookiePolicy.ACCEPT_ALL));
    8788        } catch (SecurityException e) {
    8889            Logging.log(Logging.LEVEL_ERROR, "Unable to set default cookie handler", e);
     
    133134     */
    134135    public final Response connect(ProgressMonitor progressMonitor) throws IOException {
     136        return connect(progressMonitor, null, null);
     137    }
     138
     139    /**
     140     * Opens the HTTP connection.
     141     * @param progressMonitor progress monitor
     142     * @param authRedirectLocation The location where we will be redirected for authentication
     143     * @param authRequestProperty The authorization header to set when being redirected to the auth location
     144     * @return HTTP response
     145     * @throws IOException if any I/O error occurs
     146     * @since 18913
     147     */
     148    public final Response connect(ProgressMonitor progressMonitor, String authRedirectLocation, String authRequestProperty) throws IOException {
    135149        if (progressMonitor == null) {
    136150            progressMonitor = NullProgressMonitor.INSTANCE;
     
    184198                    maxRedirects--;
    185199                    logRequest(tr("Download redirected to ''{0}''", redirectLocation));
    186                     // Fix JOSM #21935: Avoid leaking `Authorization` header on redirects.
    187                     if (!Objects.equals(oldUrl.getHost(), this.url.getHost()) && this.getRequestHeader("Authorization") != null) {
     200                    if (authRedirectLocation != null && authRequestProperty != null && redirectLocation.startsWith(authRedirectLocation)) {
     201                        setHeader("Authorization", authRequestProperty);
     202                    } else if (!Objects.equals(oldUrl.getHost(), this.url.getHost()) && this.getRequestHeader("Authorization") != null) {
     203                        // Fix JOSM #21935: Avoid leaking `Authorization` header on redirects.
    188204                        logRequest(tr("Download redirected to different host (''{0}'' -> ''{1}''), removing authorization headers",
    189205                                oldUrl.getHost(), url.getHost()));
Note: See TracChangeset for help on using the changeset viewer.