Skip to content

fix(sdk): block credential-leaking redirects and silent body truncation - #38

Merged
shreyanshjain7174 merged 2 commits into
mainfrom
fix/sdk-redirect-and-body-limit
Oct 4, 2026
Merged

shreyanshjain7174 merged 2 commits into
mainfrom
fix/sdk-redirect-and-body-limit

Conversation

@shreyanshjain7174

Copy link
Copy Markdown
Contributor

Threat

  • Same-host redirects could forward Authorization across an HTTPS to HTTP downgrade.
  • Cross-host or cross-port redirects could expose credentials through custom redirect behavior.
  • Oversized gateway responses were silently truncated and then parsed.
  • Non-JSON response bodies could be copied into SDK error text without a bound.

Fix

  • Reject HTTPS to HTTP and cross-host redirects.
  • Allow at most 3 same-origin redirect hops.
  • Read 10 MiB plus 1 byte and reject overflow explicitly.
  • Limit sanitized non-JSON error snippets to 200 bytes.
  • Preserve custom HTTP transports and redirect policies after security checks.

Tests

  • Block HTTPS to HTTP redirects and verify the destination receives no authorization header.
  • Block cross-host redirects.
  • Allow same-origin redirects and exactly 3 hops.
  • Reject a 4th redirect hop.
  • Reject oversized bodies and accept an exact-limit body.
  • Strip control characters and truncate non-JSON error bodies.
  • Pass build, vet, formatting, race, package, and full repository tests.

Signed-off-by: Shreyansh Sancheti <43677304+shreyanshjain7174@users.noreply.github.com>
Signed-off-by: Shreyansh Sancheti <43677304+shreyanshjain7174@users.noreply.github.com>
@shreyanshjain7174
shreyanshjain7174 merged commit 36d0d3e into main Oct 4, 2026
1 check passed
@shreyanshjain7174
shreyanshjain7174 deleted the fix/sdk-redirect-and-body-limit branch October 4, 2026 10:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant