mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-29 20:07:30 +09:00
[network] Stop accepting nameless cookies.
This commit is contained in:
parent
3f297457d8
commit
cdc8127cd1
1 changed files with 11 additions and 6 deletions
|
|
@ -3126,6 +3126,15 @@ nsCookieService::SetCookieInternal(nsIURI *aHostURI,
|
||||||
return newCookie;
|
return newCookie;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// RFC 6265 *explicitly* forbids nameless cookies (5.2 step 5)
|
||||||
|
// Note: we ignore RFC 6265 (bis)'s conflicting stipulation and treat equal-less cookies
|
||||||
|
// as value-less cookies, not nameless ones.
|
||||||
|
// This aligns with webkit/Safari and avoids serious sec issues like CVE-2025-8037.
|
||||||
|
if (cookieAttributes.name.IsEmpty()) {
|
||||||
|
COOKIE_LOGFAILURE(SET_COOKIE, aHostURI, savedCookieHeader, "nameless cookies are not allowed");
|
||||||
|
return newCookie;
|
||||||
|
}
|
||||||
|
|
||||||
// domain & path checks
|
// domain & path checks
|
||||||
if (!CheckDomain(cookieAttributes, aHostURI, aKey.mBaseDomain, aRequireHostMatch)) {
|
if (!CheckDomain(cookieAttributes, aHostURI, aKey.mBaseDomain, aRequireHostMatch)) {
|
||||||
COOKIE_LOGFAILURE(SET_COOKIE, aHostURI, savedCookieHeader, "failed the domain tests");
|
COOKIE_LOGFAILURE(SET_COOKIE, aHostURI, savedCookieHeader, "failed the domain tests");
|
||||||
|
|
@ -3574,15 +3583,11 @@ nsCookieService::ParseAttributes(nsDependentCString &aCookieHeader,
|
||||||
|
|
||||||
// extract cookie <NAME> & <VALUE> (first attribute), and copy the strings.
|
// extract cookie <NAME> & <VALUE> (first attribute), and copy the strings.
|
||||||
// if we find multiple cookies, return for processing
|
// if we find multiple cookies, return for processing
|
||||||
// note: if there's no '=', we assume token is <VALUE>. this is required by
|
// note: if there's no '=', we assume token is <NAME>.
|
||||||
// some sites (see bug 169091).
|
|
||||||
// XXX fix the parser to parse according to <VALUE> grammar for this case
|
|
||||||
newCookie = GetTokenValue(cookieStart, cookieEnd, tokenString, tokenValue, equalsFound);
|
newCookie = GetTokenValue(cookieStart, cookieEnd, tokenString, tokenValue, equalsFound);
|
||||||
if (equalsFound) {
|
|
||||||
aCookieAttributes.name = tokenString;
|
aCookieAttributes.name = tokenString;
|
||||||
|
if (equalsFound) {
|
||||||
aCookieAttributes.value = tokenValue;
|
aCookieAttributes.value = tokenValue;
|
||||||
} else {
|
|
||||||
aCookieAttributes.value = tokenString;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// extract remaining attributes
|
// extract remaining attributes
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue