Skip to content

strip userinfo from the absolute-form proxy request target - #2258

Merged
hyperxpro merged 1 commit into
AsyncHttpClient:mainfrom
madib06ops:proxy-request-uri-userinfo
Jul 23, 2026
Merged

strip userinfo from the absolute-form proxy request target#2258
hyperxpro merged 1 commit into
AsyncHttpClient:mainfrom
madib06ops:proxy-request-uri-userinfo

Conversation

@madib06ops

Copy link
Copy Markdown
Contributor

When a plaintext request goes through an HTTP proxy, requestUri() builds the absolute-form request target with Uri.toUrl(), which embeds the userinfo, so a request for http://user:secret@origin.example.com/resource sends those credentials to the proxy in the clear on the request line and into its access log. RFC 9110 section 4.2.4 says a sender must not generate the userinfo subcomponent when a request target is built. The sibling paths already comply: CONNECT uses getAuthority(), the Host header comes from hostHeader(uri), and the HTTP/2 path runs stripUserInfo() before setting :authority, so only the HTTP/1.1 absolute-form branch was missed. Kept toUrl() and the caller-visible Request.getUrl() unchanged and added a variant that omits the userinfo, with a test that fails on the current request line.

@hyperxpro
hyperxpro merged commit b9b744f into AsyncHttpClient:mainJul 23, 2026
13 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@madib06ops@hyperxpro