Bug #67792 [Ver->Csd]: HTTP Authorization schema names are treated as case-sensitive

From: Date: Fri, 23 Apr 2021 14:13:28 +0000
Subject: Bug #67792 [Ver->Csd]: HTTP Authorization schema names are treated as case-sensitive
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233562@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67792&edit=1

 ID:                 67792
 Updated by:         cmb@php.net
 Reported by:        bcundal at cundal dot net
 Summary:            HTTP Authorization schema names are treated as
                     case-sensitive
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            HTTP related
 PHP Version:        5.6Git-2014-08-05 (Git)
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Fixed: <https://github.com/php/php-src/commit/39ddf6b89cc5013f6e1ded90a238cd8b610e6597>


Previous Comments:
------------------------------------------------------------------------
[2021-04-22 16:27:03] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #67792: HTTP Authorization schemes are treated as case-sensitive
On GitHub:  https://github.com/php/php-src/pull/6900
Patch:      https://github.com/php/php-src/pull/6900.patch

------------------------------------------------------------------------
[2021-04-22 16:14:22] cmb@php.net

While RFC 2617 is obsoleted, RFC 7617 explicitly mentions that
"both scheme and parameter names are matched
case-insensitively"[1].  RFC 7616[2] doesn't explicitly specificy
this, but Appendix A descibes the changes from RFC 2617, and
doesn't mention case-(in)sensitivity, so we can assume that
"Digest" also has to be treated case-insensitive.

[1] <https://tools.ietf.org/html/rfc7617#section-2>
[2] <https://tools.ietf.org/html/rfc7616>

------------------------------------------------------------------------
[2014-08-05 18:50:52] bcundal at cundal dot net

Description:
------------
php_handle_auth_data treats the Authorization scheme (i.e. "Basic" or "Digest")
as case-sensitive, but RFC 2617 section 1.2 describes this token as case-insensitive.

All instances of strncmp in php_handle_auth_data should be replaced with strnicmp.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67792&edit=1


Thread (4 messages)

« previous php.bugs (#233562) next »