Bug #53010

UsernamePasswordHttpBasic disabled since .htaccess strips "Basic"

Added by Stephan Schuler almost 8 years ago. Updated about 7 years ago.

Status:
Resolved
Priority:
Must have
Assignee:
-
Category:
Security
Target version:
-
Start date:
2013-10-21
Due date:
% Done:

100%

Estimated time:
PHP Version:
Has patch:
No
Complexity:

Description

Hey there.

The Token\UsernamePasswordHttpBasic requires the "Authentication" header to begin with "Basic". That's fine since this very token is only meant to deal with basic auth requests.

Unfortunately the .htaccess file which gets installed contains the following line:

SetEnvIfNoCase Authorization "Basic ([a-zA-Z0-9\+/=]+)" REMOTE_AUTHORIZATION=$1

This means: Whenever the "Authorization Basic" header is set, it gets passed to the REMOTE_AUTHORIZATION environment variable by stripping the "Basic" string.

#1

Updated by Gerrit Code Review almost 8 years ago

  • Status changed from New to Under Review

Patch set 1 for branch master has been pushed to the review server.
It is available at https://review.typo3.org/24936

#2

Updated by Karsten Dambekalns over 7 years ago

  • Category set to Security
#3

Updated by Gerrit Code Review over 7 years ago

Patch set 2 for branch master of project Packages/TYPO3.Flow has been pushed to the review server.
It is available at https://review.typo3.org/24936

#4

Updated by Gerrit Code Review over 7 years ago

Patch set 3 for branch master of project Packages/TYPO3.Flow has been pushed to the review server.
It is available at https://review.typo3.org/24936

#5

Updated by Gerrit Code Review about 7 years ago

Patch set 4 for branch master of project Packages/TYPO3.Flow has been pushed to the review server.
It is available at http://review.typo3.org/24936

#6

Updated by Gerrit Code Review about 7 years ago

Patch set 1 for branch 2.2 of project Packages/TYPO3.Flow has been pushed to the review server.
It is available at http://review.typo3.org/32389

#7

Updated by Gerrit Code Review about 7 years ago

Patch set 1 for branch 2.1 of project Packages/TYPO3.Flow has been pushed to the review server.
It is available at http://review.typo3.org/32390

#8

Updated by Stephan Schuler about 7 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100

Also available in: Atom PDF