샘플
Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336).
sha256:ca2c5fb0a4c0366c9e1e2ca07cd75ca1c776ff2e9eab90fc258851b1d37fefe6
PUBLISHED
L3_CONTRACT_PASS
MIT-0
케이스
- 목표
- Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336). HOW
- 패키지
- net/http go1.26.5
- 환경
- go
- 생성일
- 2026-08-16T14:53:27Z
흔히 이렇게 알고 있다
Once net/http drops Authorization for a cross-domain redirect, the header stays absent for the rest of the chain — but before go1.23.7 / go1.24.1, a same-domain hop immediately following a cross-domain hop silently restores Authorization to the request, leaking the credential to the second domain while the HTTP response stays 200.
이 샘플의 작성자가 여기서 개발자나 모델이 기대할 법한 내용으로 적어둔 것이다. 아래 계약이 실제로 실행된 것이다.
컨트랙트
- After a three-hop redirect chain where the first cross-domain hop strips Authorization, the Authorization header must be absent at the same-domain second hop on serverB — before go1.23.7 / go1.24.1 this assertion fails silently with a 200 response.
- net/http does not restore Authorization on a same-domain redirect that follows a cross-domain redirect.
파일
- NOTES.md
- csx.json
- go.mod
- redirect_header_test.go
검증된 아티팩트 내려받기 (tar.gz) — 컨트랙트가 실제로 실행된 바로 그 바이트
오리진 시더
검증 영수증
- go 1.26 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-16 · ed25519:d91480838ac982c9