Copilot commented on code in PR #13420:
URL: https://github.com/apache/trafficserver/pull/13420#discussion_r4151864170


##########
src/proxy/hdrs/VersionConverter.cc:
##########
@@ -200,8 +201,27 @@ VersionConverter::_convert_req_from_2_to_1(HTTPHdr 
&header) const
   // :authority
   if (MIMEField *field = header.field_find(PSEUDO_HEADER_AUTHORITY);
       field != nullptr && field->value_is_valid(is_control_BIT | is_ws_BIT)) {
-    auto authority{field->value_get()};
-    header.m_http->u.req.m_url_impl->set_host(header.m_heap, authority, true);
+    auto value{field->value_get()};
+
+    // No host to parse, and url_parse_internet() reads *start before checking 
the length.
+    if (value.empty()) {
+      return ParseResult::ERROR;
+    }
+
+    // Copy out first: allocating from header.m_heap may coalesce it and free 
the field's storage.
+    ts::LocalBuffer<char> buf(value.length());
+    std::string_view      authority{buf.data(), value.length()};
+
+    std::copy(value.begin(), value.end(), buf.data());
+
+    // Require full consumption: url_parse_internet() stops at a '/', '?' or 
'#'.
+    const char *astart = authority.data();
+    const char *aend   = authority.data() + authority.length();
+
+    if (url_parse_internet(header.m_heap, header.m_http->u.req.m_url_impl, 
&astart, aend, true, true) != ParseResult::DONE ||
+        astart != aend) {
+      return ParseResult::ERROR;
+    }

Review Comment:
   The parsed authority can still contain userinfo. For a CONNECT request there 
is no synthesized `Host` field, so `parse_req_would_accept()` never rejects it; 
with `strict_uri_parsing=1`, an authority such as `a"@example.com:443` now 
takes the direct path even though the former serialized request target was 
rejected by `parse_req()`. RFC 9113 also forbids userinfo in `:authority`. 
Reject a parsed user/password here so CONNECT requests fall back to the 
existing 400 path too.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to