fix(jwt-auth): harden cookie token parsing (#4153)

Signed-off-by: EndlessSeeker <1766508902@qq.com>
This commit is contained in:
EndlessSeeker
2026-07-17 14:23:19 +08:00
committed by GitHub
parent 58773cb98e
commit 45942d90b6
2 changed files with 53 additions and 2 deletions

View File

@@ -129,8 +129,8 @@ func findCookie(cookie string, key string) string {
for _, pair := range pairs {
pair = strings.TrimSpace(pair)
kv := strings.Split(pair, "=")
if kv[0] == key {
kv := strings.SplitN(pair, "=", 2)
if len(kv) == 2 && kv[0] == key {
value = kv[1]
break
}

View File

@@ -0,0 +1,51 @@
package handler
import "testing"
func TestFindCookie(t *testing.T) {
tests := []struct {
name string
cookie string
key string
want string
}{
{
name: "extracts matching cookie value",
cookie: "user=alice; other=value",
key: "user",
want: "alice",
},
{
name: "skips segment without equals sign",
cookie: "user; other=value",
key: "user",
want: "",
},
{
name: "keeps equals signs in cookie value",
cookie: "user=alice=admin; other=value",
key: "user",
want: "alice=admin",
},
{
name: "empty cookie returns empty",
cookie: "",
key: "user",
want: "",
},
{
name: "key not present returns empty",
cookie: "user=alice; other=value",
key: "missing",
want: "",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
if got := findCookie(tt.cookie, tt.key); got != tt.want {
t.Fatalf("findCookie() = %q, want %q", got, tt.want)
}
})
}
}