dxbjavid opened a new pull request, #876:
URL: https://github.com/apache/httpcomponents-client/pull/876

   PublicSuffixMatcher.verify (through verifyInternal) resolves the domain 
against the suffix rules without the normalisation and punycode decoding that 
getDomainRoot and matches already apply, and the bundled list holds IDN 
suffixes in their Unicode form. So an ACE-encoded public suffix such as 
xn--h-2fa.no matches no rule and verify returns true, which lets the cookie 
PublicSuffixDomainFilter treat a whole IDN TLD as a registrable domain and 
accept a supercookie scoped to it, even though matches recognises the same 
suffix correctly. This decodes and lowercases the input in verifyInternal the 
same way getDomainRoot does, so both the ACE and Unicode forms are rejected 
consistently while genuine registrable subdomains under an IDN suffix are still 
allowed.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to