fix(http): check delete request errors before auth (#9784)

Explain:

- problem: Delete and DeleteProxied could panic on malformed URLs when a JWT was provided.

- root cause: maybeAddAuth was called before checking the error returned by http.NewRequest, so req could be nil.

- fix: return the request construction error before adding the Authorization header.

- validation: go test ./weed/util/http -run 'TestDelete(ReturnsInvalidRequestErrorBeforeAddingAuth|ProxiedReturnsInvalidRequestErrorBeforeAddingAuth)' -count=1; git diff --check
This commit is contained in:
7y-9
2026-06-02 00:41:17 -07:00
committed by GitHub
parent 2a46d457ac
commit 38a47d1dd3
2 changed files with 26 additions and 3 deletions
+2 -2
View File
@@ -144,10 +144,10 @@ func maybeAddAuth(req *http.Request, jwt string) {
func Delete(url string, jwt string) error {
req, err := http.NewRequest(http.MethodDelete, url, nil)
maybeAddAuth(req, jwt)
if err != nil {
return err
}
maybeAddAuth(req, jwt)
resp, e := GetGlobalHttpClient().Do(req)
if e != nil {
return e
@@ -172,10 +172,10 @@ func Delete(url string, jwt string) error {
func DeleteProxied(url string, jwt string) (body []byte, httpStatus int, err error) {
req, err := http.NewRequest(http.MethodDelete, url, nil)
maybeAddAuth(req, jwt)
if err != nil {
return
}
maybeAddAuth(req, jwt)
resp, err := GetGlobalHttpClient().Do(req)
if err != nil {
return
+24 -1
View File
@@ -75,7 +75,6 @@ func TestAppendQueryParameter(t *testing.T) {
})
}
}
func TestReadUrlAsStreamReturnsGzipReaderError(t *testing.T) {
InitGlobalHttpClient()
@@ -91,3 +90,27 @@ func TestReadUrlAsStreamReturnsGzipReaderError(t *testing.T) {
t.Fatal("ReadUrlAsStream returned nil error for invalid gzip response")
}
}
func TestDeleteReturnsInvalidRequestErrorBeforeAddingAuth(t *testing.T) {
defer func() {
if r := recover(); r != nil {
t.Fatalf("Delete panicked before returning the request error: %v", r)
}
}()
if err := Delete("http://[::1", "jwt"); err == nil {
t.Fatal("expected invalid request error")
}
}
func TestDeleteProxiedReturnsInvalidRequestErrorBeforeAddingAuth(t *testing.T) {
defer func() {
if r := recover(); r != nil {
t.Fatalf("DeleteProxied panicked before returning the request error: %v", r)
}
}()
if _, _, err := DeleteProxied("http://[::1", "jwt"); err == nil {
t.Fatal("expected invalid request error")
}
}