https://bugzilla.redhat.com/show_bug.cgi?id=1032089
Bug ID: 1032089 Summary: HTTP authentication is buggy Product: Fedora Version: 20 Component: perl-HTTP-Tiny Assignee: ppisar@redhat.com Reporter: ppisar@redhat.com QA Contact: extras-qa@fedoraproject.org CC: perl-devel@lists.fedoraproject.org, ppisar@redhat.com
0.034 introduced HTTP Basic authentication. Version 0.038 fixed accidential Authorization header rewrite, version 0.037 fixed escaping the credentials. These fixes should be fixed in F20:
0.038 2013-11-18 12:56:26 America/New_York
[FIXED]
- Fixed a bug where authentication parameters in the URL would override an existing Authorization header
0.037 2013-10-28 13:26:21 America/New_York
[FIXED]
- Basic authentication in the URL is now unescaped before being encoded into the authentication header
https://bugzilla.redhat.com/show_bug.cgi?id=1032089
Petr Pisar ppisar@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- See Also| |https://bugzilla.redhat.com | |/show_bug.cgi?id=1031990
https://bugzilla.redhat.com/show_bug.cgi?id=1032089
--- Comment #1 from Petr Pisar ppisar@redhat.com --- Upstream commits:
commit 7bb424df183e34ee16de433cb1e8c18a74b4b6cb Author: David Golden dagolden@cpan.org Date: Mon Oct 28 13:23:35 2013 -0400
unescape any basic authentication stanza
commit 2897ea97557aac4d310912237b076dc1b40858e0 Author: David Golden dagolden@cpan.org Date: Mon Nov 18 12:45:06 2013 -0500
fix basic auth in URL overriding existing auth header
Basic authorization shouldn't be added if an authorization header exists. The wrong header was being checked and this commit fixes that.
https://bugzilla.redhat.com/show_bug.cgi?id=1032089
--- Comment #2 from Fedora Update System updates@fedoraproject.org --- perl-HTTP-Tiny-0.034-4.fc20 has been submitted as an update for Fedora 20. https://admin.fedoraproject.org/updates/perl-HTTP-Tiny-0.034-4.fc20
https://bugzilla.redhat.com/show_bug.cgi?id=1032089
--- Comment #3 from Fedora Update System updates@fedoraproject.org --- perl-HTTP-Tiny-0.034-4.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
https://bugzilla.redhat.com/show_bug.cgi?id=1032089
Petr Pisar ppisar@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|MODIFIED |CLOSED Resolution|--- |ERRATA Last Closed| |2014-07-02 09:15:07
perl-devel@lists.fedoraproject.org