Fix to disable Header and Authorise attributes containing CRLF#1834
Merged
Conversation
CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
Member
Author
|
@anaisbetts please take a look at this as a possible resolution, thank you. |
Member
|
Should we also change |
Member
Author
I will take a look at this assuming there's no conflict with any existing options |
|
This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
Fix
What is the current behavior?
Header and Authorise attributes could CRLF which may cause issues
What is the new behavior?
Added detection and correction of CRLF characters.
What might this PR break?
None expected
Please check if the PR fulfills these requirements
Other information: