Revanth14 commented on code in PR #2098:
URL: https://github.com/apache/iceberg-go/pull/2098#discussion_r4211012281


##########
catalog/rest/rest.go:
##########
@@ -1046,6 +1072,8 @@ func (r *Catalog) createSession(ctx context.Context, opts 
*options) (*http.Clien
        session := &sessionTransport{
                RoundTripper:   baseTransport,
                defaultHeaders: http.Header{},
+               catalogOrigin:  r.baseURI,
+               authOrigin:     opts.authUri,

Review Comment:
   Done in this PR. All three clients refuse cross-origin redirects: the 
catalog client and both OAuth token clients, including the separate one built 
for `WithOAuthTLSConfig`. A redirect is followed only while it stays on the 
origin of the original request. The error wraps `ErrRESTError` and names both 
origins, and the 10-redirect limit is kept.
   
   I didn't add an `authOrigin` exception. Each chain stays on the origin it 
started on, so token requests stay on the token endpoint's origin and catalog 
requests stay on the catalog origin.
   
   Tests:
   - `TestTokenRequestCrossOriginRedirectNotFollowed`: `client_secret` never 
reaches the other origin, through the catalog token endpoint, `WithAuthURI`, or 
`WithOAuthTLSConfig`.
   - `TestDropTableCrossOriginRedirectNotFollowed`: neither the other origin 
nor a different table is contacted.
   - `TestCrossOriginRedirectNotFollowed`: also covers same-origin redirects 
and the loop limit.
   
   Each client's `CheckRedirect` was removed in turn to confirm its test fails. 
The behavior change is called out in the description.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to