mirror of
https://github.com/servo/servo.git
synced 2025-07-23 07:13:52 +01:00
disallow restricted XMLHttpRequest header prefixes
This commit is contained in:
parent
aaad24c531
commit
c375ad5e95
3 changed files with 20 additions and 24 deletions
|
@ -423,20 +423,26 @@ impl XMLHttpRequestMethods for XMLHttpRequest {
|
||||||
let name_lower = name.to_lower();
|
let name_lower = name.to_lower();
|
||||||
let name_str = match name_lower.as_str() {
|
let name_str = match name_lower.as_str() {
|
||||||
Some(s) => {
|
Some(s) => {
|
||||||
match s {
|
// Step 5
|
||||||
// Step 5
|
// Disallowed headers and header prefixes:
|
||||||
// Disallowed headers
|
// https://www.w3.org/TR/XMLHttpRequest/#the-setrequestheader-method
|
||||||
"accept-charset" | "accept-encoding" |
|
let disallowedHeaders =
|
||||||
"access-control-request-headers" |
|
["accept-charset", "accept-encoding",
|
||||||
"access-control-request-method" |
|
"access-control-request-headers",
|
||||||
"connection" | "content-length" |
|
"access-control-request-method",
|
||||||
"cookie" | "cookie2" | "date" |"dnt" |
|
"connection", "content-length",
|
||||||
"expect" | "host" | "keep-alive" | "origin" |
|
"cookie", "cookie2", "date", "dnt",
|
||||||
"referer" | "te" | "trailer" | "transfer-encoding" |
|
"expect", "host", "keep-alive", "origin",
|
||||||
"upgrade" | "user-agent" | "via" => {
|
"referer", "te", "trailer", "transfer-encoding",
|
||||||
return Ok(());
|
"upgrade", "user-agent", "via"];
|
||||||
},
|
|
||||||
_ => s
|
let disallowedHeaderPrefixes = ["sec-", "proxy-"];
|
||||||
|
|
||||||
|
if disallowedHeaders.iter().any(|header| *header == s) ||
|
||||||
|
disallowedHeaderPrefixes.iter().any(|prefix| s.starts_with(prefix)) {
|
||||||
|
return Ok(())
|
||||||
|
} else {
|
||||||
|
s
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
None => unreachable!()
|
None => unreachable!()
|
||||||
|
|
|
@ -1,5 +0,0 @@
|
||||||
[setrequestheader-header-forbidden.htm]
|
|
||||||
type: testharness
|
|
||||||
[XMLHttpRequest: setRequestHeader() - headers that are forbidden]
|
|
||||||
expected: FAIL
|
|
||||||
|
|
|
@ -1,5 +0,0 @@
|
||||||
[002.html]
|
|
||||||
type: testharness
|
|
||||||
[WebSockets: check Sec-WebSocket-Key]
|
|
||||||
expected: FAIL
|
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue