Skip to content

Decode URL-encoded user and password when parsing host credentials - #341

Open
magic-peach wants to merge 1 commit into
opensearch-project:mainfrom
magic-peach:fix/decode-url-encoded-credentials
Open

magic-peach wants to merge 1 commit into
opensearch-project:mainfrom
magic-peach:fix/decode-url-encoded-credentials

Conversation

@magic-peach

Copy link
Copy Markdown

Client#__parse_host extracts user and password from a host URL using URI::Generic and URI, but Ruby's URI#user and URI#password return the still percent-encoded values. Client#perform_request later calls CGI.escape on those same values when building the request URL, so a password containing reserved characters gets double encoded and the wrong password is sent to the server.

This decodes the user and password with CGI.unescape right after extracting them in Client#__parse_host, for both the String and URI branches, so the values stored on the client are the actual credentials rather than their encoded form.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here: https://github.com/opensearch-project/OpenSearch/blob/main/CONTRIBUTING.md#developer-certificate-of-origin

Signed-off-by: Akanksha Trehun <akankshatrehun@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant