mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-30 11:45:42 +00:00
fix(http): check delete request errors before auth (#9784)
Explain: - problem: Delete and DeleteProxied could panic on malformed URLs when a JWT was provided. - root cause: maybeAddAuth was called before checking the error returned by http.NewRequest, so req could be nil. - fix: return the request construction error before adding the Authorization header. - validation: go test ./weed/util/http -run 'TestDelete(ReturnsInvalidRequestErrorBeforeAddingAuth|ProxiedReturnsInvalidRequestErrorBeforeAddingAuth)' -count=1; git diff --check
This commit is contained in:
@@ -144,10 +144,10 @@ func maybeAddAuth(req *http.Request, jwt string) {
|
||||
|
||||
func Delete(url string, jwt string) error {
|
||||
req, err := http.NewRequest(http.MethodDelete, url, nil)
|
||||
maybeAddAuth(req, jwt)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
maybeAddAuth(req, jwt)
|
||||
resp, e := GetGlobalHttpClient().Do(req)
|
||||
if e != nil {
|
||||
return e
|
||||
@@ -172,10 +172,10 @@ func Delete(url string, jwt string) error {
|
||||
|
||||
func DeleteProxied(url string, jwt string) (body []byte, httpStatus int, err error) {
|
||||
req, err := http.NewRequest(http.MethodDelete, url, nil)
|
||||
maybeAddAuth(req, jwt)
|
||||
if err != nil {
|
||||
return
|
||||
}
|
||||
maybeAddAuth(req, jwt)
|
||||
resp, err := GetGlobalHttpClient().Do(req)
|
||||
if err != nil {
|
||||
return
|
||||
|
||||
@@ -75,7 +75,6 @@ func TestAppendQueryParameter(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestReadUrlAsStreamReturnsGzipReaderError(t *testing.T) {
|
||||
InitGlobalHttpClient()
|
||||
|
||||
@@ -91,3 +90,27 @@ func TestReadUrlAsStreamReturnsGzipReaderError(t *testing.T) {
|
||||
t.Fatal("ReadUrlAsStream returned nil error for invalid gzip response")
|
||||
}
|
||||
}
|
||||
|
||||
func TestDeleteReturnsInvalidRequestErrorBeforeAddingAuth(t *testing.T) {
|
||||
defer func() {
|
||||
if r := recover(); r != nil {
|
||||
t.Fatalf("Delete panicked before returning the request error: %v", r)
|
||||
}
|
||||
}()
|
||||
|
||||
if err := Delete("http://[::1", "jwt"); err == nil {
|
||||
t.Fatal("expected invalid request error")
|
||||
}
|
||||
}
|
||||
|
||||
func TestDeleteProxiedReturnsInvalidRequestErrorBeforeAddingAuth(t *testing.T) {
|
||||
defer func() {
|
||||
if r := recover(); r != nil {
|
||||
t.Fatalf("DeleteProxied panicked before returning the request error: %v", r)
|
||||
}
|
||||
}()
|
||||
|
||||
if _, _, err := DeleteProxied("http://[::1", "jwt"); err == nil {
|
||||
t.Fatal("expected invalid request error")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user