Thread (6 messages) 6 messages, 3 authors, 2026-05-22

Re: [PATCH] http: handle absolute-path alternates from server root

flat view

From: Junio C Hamano <hidden>
Date: 2026-05-13 01:10:57

Jeff King [off-list ref] writes:
          ... Probably in a way that makes it totally invalid, but
          if you were very unlucky you could turn something like:

             http://victim.com.evil.domain:8000

          into:

            http://victim.com

	  Which looks like the start of a redirect attack, except that
	  the attacker could just have written "http://victim.com" in
	  the first place! Either way we feed it to
	  is_alternate_allowed(), which is where we check redirect and
	  protocol rules.
Yuck.  I know I am the guilty party who introduced the dumb HTTP
walker but I wish we could kill it off after all these years. I did
not even recall that we supported the alternate object store in the
"protocol" until I saw this patch X-<.
I think we can just treat this like a regular bug.
Absolutely.  Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help