mirror of
https://github.com/alibaba/higress.git
synced 2026-07-23 21:00:41 +08:00
fix(jwt-auth): harden cookie token parsing (#4153)
Signed-off-by: EndlessSeeker <1766508902@qq.com>
This commit is contained in:
@@ -129,8 +129,8 @@ func findCookie(cookie string, key string) string {
|
||||
|
||||
for _, pair := range pairs {
|
||||
pair = strings.TrimSpace(pair)
|
||||
kv := strings.Split(pair, "=")
|
||||
if kv[0] == key {
|
||||
kv := strings.SplitN(pair, "=", 2)
|
||||
if len(kv) == 2 && kv[0] == key {
|
||||
value = kv[1]
|
||||
break
|
||||
}
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
package handler
|
||||
|
||||
import "testing"
|
||||
|
||||
func TestFindCookie(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
cookie string
|
||||
key string
|
||||
want string
|
||||
}{
|
||||
{
|
||||
name: "extracts matching cookie value",
|
||||
cookie: "user=alice; other=value",
|
||||
key: "user",
|
||||
want: "alice",
|
||||
},
|
||||
{
|
||||
name: "skips segment without equals sign",
|
||||
cookie: "user; other=value",
|
||||
key: "user",
|
||||
want: "",
|
||||
},
|
||||
{
|
||||
name: "keeps equals signs in cookie value",
|
||||
cookie: "user=alice=admin; other=value",
|
||||
key: "user",
|
||||
want: "alice=admin",
|
||||
},
|
||||
{
|
||||
name: "empty cookie returns empty",
|
||||
cookie: "",
|
||||
key: "user",
|
||||
want: "",
|
||||
},
|
||||
{
|
||||
name: "key not present returns empty",
|
||||
cookie: "user=alice; other=value",
|
||||
key: "missing",
|
||||
want: "",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
if got := findCookie(tt.cookie, tt.key); got != tt.want {
|
||||
t.Fatalf("findCookie() = %q, want %q", got, tt.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user