Project

General

Profile

Actions

Bug #85411

closed

Invalid usage of 401 header

Added by Markus Klein almost 6 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
Authentication
Target version:
-
Start date:
2018-06-27
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
8
PHP Version:
Tags:
Complexity:
easy
Is Regression:
Sprint Focus:

Description

The 401 header is used within the TYPO3 core in some usages but lacks a proper accompanying "www-authenticate" header, which is required. [1]

A 401 header is only useful in conjunction with an assigned http authschema [2].
One usage in core even sends an invalid www-authenticate header.

Replace all those 401 headers with a 403 header.

[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401
[2] http://www.iana.org/assignments/http-authschemes/http-authschemes.xhtml

Actions #1

Updated by Gerrit Code Review almost 6 years ago

  • Status changed from New to Under Review

Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/57399

Actions #2

Updated by Gerrit Code Review almost 6 years ago

Patch set 2 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/57399

Actions #3

Updated by Markus Klein over 5 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100
Actions #4

Updated by Gerrit Code Review over 5 years ago

  • Status changed from Resolved to Under Review

Patch set 1 for branch TYPO3_8-7 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/58244

Actions #5

Updated by Markus Klein over 5 years ago

  • Status changed from Under Review to Resolved
Actions #6

Updated by Benni Mack over 5 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF