Ejemplo
Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336).
sha256:ca2c5fb0a4c0366c9e1e2ca07cd75ca1c776ff2e9eab90fc258851b1d37fefe6
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Caso
- Objetivo
- Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336). HOW
- Paquetes
- net/http go1.26.5
- Entorno
- go
- Creado
- 2026-08-16T14:53:27Z
Lo que suele suponerse
Once net/http drops Authorization for a cross-domain redirect, the header stays absent for the rest of the chain — but before go1.23.7 / go1.24.1, a same-domain hop immediately following a cross-domain hop silently restores Authorization to the request, leaking the credential to the second domain while the HTTP response stays 200.
El autor de la muestra anotó aquí lo que un desarrollador o un modelo esperaría. El contrato de abajo es lo que realmente se ejecutó.
Contrato
- After a three-hop redirect chain where the first cross-domain hop strips Authorization, the Authorization header must be absent at the same-domain second hop on serverB — before go1.23.7 / go1.24.1 this assertion fails silently with a 200 response.
- net/http does not restore Authorization on a same-domain redirect that follows a cross-domain redirect.
Archivos
- NOTES.md
- csx.json
- go.mod
- redirect_header_test.go
Descargar el artefacto verificado (tar.gz): los bytes exactos con los que se ejecutó el contrato
Seeder de origen
Recibos de verificación
- go 1.26 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-16 · ed25519:d91480838ac982c9