Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Patch to fix broken HTTP Digest Authentication

#3006

Current HTTP Digest Authentication does not work with some browser/servers combinations.

For example, Webrick uses the full REQUEST_URI, while a browser like Safari or Firefox only send the relative_uri. In this case, HTTP Digest won't work.

On the other hand, IE sends the full REQUEST_URI, so it may not work with servers like mongrel or thin.

This patch attempts to let it flexible enough to work with a different combination of servers/browsers, without changing any security rule.

I tested in "real life" with Firefox on Linux on both webrick and thin. Would be nice if some tests would be executed with Safari and IE with both servers.

For some guidance, you could follow Ryan Daigle tutorial to setup: http://ryandaigle.com/articles/2009/1/30/what-s-new-in-edge-rails-h...

Reported by José Valim · August 8th, 2009 @ 11:56 AM

State: resolved
Milestone: 2.3.4
Assigned to: nobody
Importance: none

Activity

  1. Rizwan Reza
    Rizwan Reza

    Verified

    +1 This patch works in master and 2-3-stable. All tests pass.

    August 8th, 2009 @ 06:08 PM

  2. Dan Pickett
    Dan Pickett

    Verified

    +1 applied to 2-3 stable without issue

    August 8th, 2009 @ 07:44 PM

  3. Steve St. Martin
    Steve St. Martin

    Verified

    -1 This patch does not apply cleanly to master, also as poster suggests needs real world testing to ensure tests are sufficient

    August 8th, 2009 @ 09:20 PM

  4. Rizwan Reza
    Rizwan Reza

    Clarification: This only works in 2-3-stable.

    I will see how Safari and mongrel works with this now.

    August 8th, 2009 @ 11:05 PM

  5. Rizwan Reza
    Rizwan Reza

    -1 This is not working correctly with Safari. It is not redirecting to Non-authorized page on wrong password input.

    August 8th, 2009 @ 11:18 PM

  6. José Valim
    José Valim

    Rizwan, what do you get with wrong password input? It should not redirect to somewhere, just confirm that you are getting the proper http status.

    August 8th, 2009 @ 11:21 PM

  7. Elad Meidar
    Elad Meidar

    +1 Applies cleanly on 2-3-stable (tests pass), -1 fails on master.

    successfully tested manually on Safari / FF on mongrel, got unauthorized status back.

    August 9th, 2009 @ 04:18 AM

  8. José Valim
    José Valim
    • State changed from new to resolved
    • Tag changed from 2.x, 3.0, actioncontroller, bugmash to 2.x, 3.0, actioncontroller

    August 9th, 2009 @ 04:00 PM

  9. Repository