Revanth14 commented on code in PR #2098:
URL: https://github.com/apache/iceberg-go/pull/2098#discussion_r4210999105


##########
catalog/rest/rest.go:
##########
@@ -262,12 +273,22 @@ func defaultedPort(u *url.URL) string {
 }
 
 func (s *sessionTransport) RoundTrip(r *http.Request) (*http.Response, error) {
+       // net/http strips Authorization on redirect only for a new hostname (a

Review Comment:
   Rewrote it. The deeper issue was the premise: net/http's redirect stripping 
only covers headers on the request passed to `Client.Do`, and those are copied 
before the first send. The bearer, the signature and the `header.*` values are 
added by this transport on every hop, so net/http never strips them, and custom 
headers like `X-Api-Key` aren't stripped in any case. The comment now says 
that, and that the new `CheckRedirect` keeps clients from following a 
cross-origin hop in the first place, which makes this gate a second line of 
defense.
   
   On the subdomain point: Go 1.27's `shouldCopyHeaderOnRedirect` keeps 
`Authorization` for the same host or a subdomain of the original. So 
`example.com` → `foo.example.com` keeps it, and `foo.example.com` → 
`example.com` (a hop to the parent) drops it. The old wording was about the 
first case, but the new comment no longer depends on that detail.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to