mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-05 14:11:14 +02:00
fix: runtime error: index out of range (0) with length 0 (#2328)
* Issue 2311: runtime error: index out of range [0] with length 0 while extracting state of of the csrf --------- Co-authored-by: tuunit <jan@larwig.com>
This commit is contained in:
co-authored by
tuunit
parent
642ba174d4
commit
ff761d2523
+8
-15
@@ -72,9 +72,7 @@ func NewCSRF(opts *options.Cookie, codeVerifier string) (CSRF, error) {
|
||||
}
|
||||
|
||||
// LoadCSRFCookie loads a CSRF object from a request's CSRF cookie
|
||||
func LoadCSRFCookie(req *http.Request, opts *options.Cookie) (CSRF, error) {
|
||||
cookieName := GenerateCookieName(req, opts)
|
||||
|
||||
func LoadCSRFCookie(req *http.Request, cookieName string, opts *options.Cookie) (CSRF, error) {
|
||||
cookies := req.Cookies()
|
||||
for _, cookie := range cookies {
|
||||
if cookie.Name != cookieName {
|
||||
@@ -89,17 +87,17 @@ func LoadCSRFCookie(req *http.Request, opts *options.Cookie) (CSRF, error) {
|
||||
return csrf, nil
|
||||
}
|
||||
|
||||
return nil, errors.New("CSRF cookie not found")
|
||||
return nil, fmt.Errorf("CSRF cookie with name '%v' was not found", cookieName)
|
||||
}
|
||||
|
||||
// GenerateCookieName in case cookie options state that CSRF cookie has fixed name then set fixed name, otherwise
|
||||
// build name based on the state
|
||||
func GenerateCookieName(req *http.Request, opts *options.Cookie) string {
|
||||
func GenerateCookieName(opts *options.Cookie, state string) string {
|
||||
stateSubstring := ""
|
||||
if opts.CSRFPerRequest {
|
||||
// csrfCookieName will include a substring of the state to enable multiple csrf cookies
|
||||
// in case of parallel requests
|
||||
stateSubstring = ExtractStateSubstring(req)
|
||||
stateSubstring = ExtractStateSubstring(state)
|
||||
}
|
||||
return csrfCookieName(opts, stateSubstring)
|
||||
}
|
||||
@@ -218,20 +216,15 @@ func csrfCookieName(opts *options.Cookie, stateSubstring string) string {
|
||||
if stateSubstring == "" {
|
||||
return fmt.Sprintf("%v_csrf", opts.Name)
|
||||
}
|
||||
return fmt.Sprintf("%v_csrf_%v", opts.Name, stateSubstring)
|
||||
return fmt.Sprintf("%v_%v_csrf", opts.Name, stateSubstring)
|
||||
}
|
||||
|
||||
// ExtractStateSubstring extract the initial state characters, to add it to the CSRF cookie name
|
||||
func ExtractStateSubstring(req *http.Request) string {
|
||||
func ExtractStateSubstring(state string) string {
|
||||
lastChar := csrfStateLength - 1
|
||||
stateSubstring := ""
|
||||
|
||||
state := req.URL.Query()["state"]
|
||||
if state[0] != "" {
|
||||
state := state[0]
|
||||
if lastChar <= len(state) {
|
||||
stateSubstring = state[0:lastChar]
|
||||
}
|
||||
if lastChar <= len(state) {
|
||||
stateSubstring = state[0:lastChar]
|
||||
}
|
||||
return stateSubstring
|
||||
}
|
||||
|
||||
@@ -19,6 +19,7 @@ var _ = Describe("CSRF Cookie Tests", func() {
|
||||
cookieOpts *options.Cookie
|
||||
publicCSRF CSRF
|
||||
privateCSRF *csrf
|
||||
csrfName string
|
||||
)
|
||||
|
||||
BeforeEach(func() {
|
||||
@@ -39,6 +40,7 @@ var _ = Describe("CSRF Cookie Tests", func() {
|
||||
Expect(err).ToNot(HaveOccurred())
|
||||
|
||||
privateCSRF = publicCSRF.(*csrf)
|
||||
csrfName = GenerateCookieName(cookieOpts, csrfNonce)
|
||||
})
|
||||
|
||||
Context("NewCSRF", func() {
|
||||
@@ -175,7 +177,7 @@ var _ = Describe("CSRF Cookie Tests", func() {
|
||||
})
|
||||
|
||||
It("should return error when no cookie is set", func() {
|
||||
csrf, err := LoadCSRFCookie(req, cookieOpts)
|
||||
csrf, err := LoadCSRFCookie(req, csrfName, cookieOpts)
|
||||
Expect(err).To(HaveOccurred())
|
||||
Expect(csrf).To(BeNil())
|
||||
})
|
||||
@@ -191,7 +193,7 @@ var _ = Describe("CSRF Cookie Tests", func() {
|
||||
Value: encoded,
|
||||
})
|
||||
|
||||
csrf, err := LoadCSRFCookie(req, cookieOpts)
|
||||
csrf, err := LoadCSRFCookie(req, csrfName, cookieOpts)
|
||||
Expect(err).ToNot(HaveOccurred())
|
||||
Expect(csrf).ToNot(BeNil())
|
||||
})
|
||||
@@ -202,7 +204,7 @@ var _ = Describe("CSRF Cookie Tests", func() {
|
||||
Value: "invalid",
|
||||
})
|
||||
|
||||
csrf, err := LoadCSRFCookie(req, cookieOpts)
|
||||
csrf, err := LoadCSRFCookie(req, csrfName, cookieOpts)
|
||||
Expect(err).To(HaveOccurred())
|
||||
Expect(csrf).To(BeNil())
|
||||
})
|
||||
@@ -223,7 +225,7 @@ var _ = Describe("CSRF Cookie Tests", func() {
|
||||
Value: encoded,
|
||||
})
|
||||
|
||||
csrf, err := LoadCSRFCookie(req, cookieOpts)
|
||||
csrf, err := LoadCSRFCookie(req, csrfName, cookieOpts)
|
||||
Expect(err).ToNot(HaveOccurred())
|
||||
Expect(csrf).ToNot(BeNil())
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user