Revanth14 commented on code in PR #2098:
URL: https://github.com/apache/iceberg-go/pull/2098#discussion_r4211012281
##########
catalog/rest/rest.go:
##########
@@ -1046,6 +1072,8 @@ func (r *Catalog) createSession(ctx context.Context, opts
*options) (*http.Clien
session := &sessionTransport{
RoundTripper: baseTransport,
defaultHeaders: http.Header{},
+ catalogOrigin: r.baseURI,
+ authOrigin: opts.authUri,
Review Comment:
Done in this PR. All three clients refuse cross-origin redirects: the
catalog client and both OAuth token clients, including the separate one built
for `WithOAuthTLSConfig`. A redirect is followed only while it stays on the
origin of the original request. The error wraps `ErrRESTError` and names both
origins, and the 10-redirect limit is kept.
I didn't add an `authOrigin` exception. Each chain stays on the origin it
started on, so token requests stay on the token endpoint's origin and catalog
requests stay on the catalog origin.
Tests:
- `TestTokenRequestCrossOriginRedirectNotFollowed`: `client_secret` never
reaches the other origin, through the catalog token endpoint, `WithAuthURI`, or
`WithOAuthTLSConfig`.
- `TestDropTableCrossOriginRedirectNotFollowed`: neither the other origin
nor a different table is contacted.
- `TestCrossOriginRedirectNotFollowed`: also covers same-origin redirects
and the loop limit.
Each client's `CheckRedirect` was removed in turn to confirm its test fails.
The behavior change is called out in the description.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]