Try to avoid host header misconfigurations in check_signature().

This commit is contained in:
default 2024-01-03 09:22:07 +01:00
parent 6bd8aed25d
commit 607335aa74

13
http.c
View file

@ -223,6 +223,19 @@ int check_signature(xs_dict *req, xs_str **err)
if (strcmp(v, "(expires)") == 0) {
ss = xs_fmt("%s: %s", v, expires);
}
else
if (strcmp(v, "host") == 0) {
hc = xs_dict_get(req, "host");
/* if there is no host header or some garbage like
address:host has arrived here due to misconfiguration,
signature verify will totally fail, so let's Leroy Jenkins
with the global server hostname instead */
if (hc == NULL || xs_str_in(hc, ":") != -1)
hc = xs_dict_get(srv_config, "host");
ss = xs_fmt("host: %s", hc);
}
else {
/* add the header */
if ((hc = xs_dict_get(req, v)) == NULL) {