Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

[Patch] Fixed basic auth with long credentials

#2572

This patch fixes the http_basic_auth with long credentials.

A long username/password results in a (base64 encoded) request header string that contains newlines (\n). When decoding, Rails splitted the header with "split()" and used only the last part of the result. With the patch it splits it in max. two parts "split(' ', 2)".

Reported by Jan · April 27th, 2009 @ 07:33 PM

State: resolved
Milestone: 2.x
Assigned to: nobody
Importance: none

Activity

  1. robert
  2. Peter Wagenet
    Peter Wagenet

    Theory looks solid. Haven't tested it yet however.

    April 29th, 2009 @ 07:49 PM

  3. David Dollar
    David Dollar

    Looks good, tests pass. +1

    April 29th, 2009 @ 08:32 PM

  4. Clemens Kofler
    Clemens Kofler

    +1 from me. Looks good.

    May 13th, 2009 @ 04:53 PM

  5. Jan
    Jan
    • Tag changed from basic_auth, patch to basic_auth, patch, verified

    May 13th, 2009 @ 04:55 PM

  6. Repository
    Repository
    • State changed from new to resolved

    (from [1f6afe4a74bb815a33f41b2d75acd530de6e2eba]) Fix HTTP basic authentication for long credentials [#2572 state:resolved]

    Signed-off-by: Pratik Naik pratiknaik@gmail.com
    http://github.com/rails/rails/commit/1f6afe4a74bb815a33f41b2d75acd5...

    August 9th, 2009 @ 05:25 AM

  7. Repository