From 38a47d1dd39a024d6d32fe5a934c73d93b943859 Mon Sep 17 00:00:00 2001 From: 7y-9 Date: Tue, 2 Jun 2026 15:41:17 +0800 Subject: [PATCH] fix(http): check delete request errors before auth (#9784) Explain: - problem: Delete and DeleteProxied could panic on malformed URLs when a JWT was provided. - root cause: maybeAddAuth was called before checking the error returned by http.NewRequest, so req could be nil. - fix: return the request construction error before adding the Authorization header. - validation: go test ./weed/util/http -run 'TestDelete(ReturnsInvalidRequestErrorBeforeAddingAuth|ProxiedReturnsInvalidRequestErrorBeforeAddingAuth)' -count=1; git diff --check --- weed/util/http/http_global_client_util.go | 4 +-- .../util/http/http_global_client_util_test.go | 25 ++++++++++++++++++- 2 files changed, 26 insertions(+), 3 deletions(-) diff --git a/weed/util/http/http_global_client_util.go b/weed/util/http/http_global_client_util.go index 1a78bd412..a4f3941b6 100644 --- a/weed/util/http/http_global_client_util.go +++ b/weed/util/http/http_global_client_util.go @@ -144,10 +144,10 @@ func maybeAddAuth(req *http.Request, jwt string) { func Delete(url string, jwt string) error { req, err := http.NewRequest(http.MethodDelete, url, nil) - maybeAddAuth(req, jwt) if err != nil { return err } + maybeAddAuth(req, jwt) resp, e := GetGlobalHttpClient().Do(req) if e != nil { return e @@ -172,10 +172,10 @@ func Delete(url string, jwt string) error { func DeleteProxied(url string, jwt string) (body []byte, httpStatus int, err error) { req, err := http.NewRequest(http.MethodDelete, url, nil) - maybeAddAuth(req, jwt) if err != nil { return } + maybeAddAuth(req, jwt) resp, err := GetGlobalHttpClient().Do(req) if err != nil { return diff --git a/weed/util/http/http_global_client_util_test.go b/weed/util/http/http_global_client_util_test.go index cc17301e3..487d23768 100644 --- a/weed/util/http/http_global_client_util_test.go +++ b/weed/util/http/http_global_client_util_test.go @@ -75,7 +75,6 @@ func TestAppendQueryParameter(t *testing.T) { }) } } - func TestReadUrlAsStreamReturnsGzipReaderError(t *testing.T) { InitGlobalHttpClient() @@ -91,3 +90,27 @@ func TestReadUrlAsStreamReturnsGzipReaderError(t *testing.T) { t.Fatal("ReadUrlAsStream returned nil error for invalid gzip response") } } + +func TestDeleteReturnsInvalidRequestErrorBeforeAddingAuth(t *testing.T) { + defer func() { + if r := recover(); r != nil { + t.Fatalf("Delete panicked before returning the request error: %v", r) + } + }() + + if err := Delete("http://[::1", "jwt"); err == nil { + t.Fatal("expected invalid request error") + } +} + +func TestDeleteProxiedReturnsInvalidRequestErrorBeforeAddingAuth(t *testing.T) { + defer func() { + if r := recover(); r != nil { + t.Fatalf("DeleteProxied panicked before returning the request error: %v", r) + } + }() + + if _, _, err := DeleteProxied("http://[::1", "jwt"); err == nil { + t.Fatal("expected invalid request error") + } +}