fix(jwt-auth): harden cookie token parsing (#4153)

Signed-off-by: EndlessSeeker <1766508902@qq.com>
This commit is contained in:
EndlessSeeker
2026-07-17 14:23:19 +08:00
committed by GitHub
parent 58773cb98e
commit 45942d90b6
2 changed files with 53 additions and 2 deletions

View File

@@ -129,8 +129,8 @@ func findCookie(cookie string, key string) string {
for _, pair := range pairs {
pair = strings.TrimSpace(pair)
kv := strings.Split(pair, "=")
if kv[0] == key {
kv := strings.SplitN(pair, "=", 2)
if len(kv) == 2 && kv[0] == key {
value = kv[1]
break
}