Fix out-of-range panic on malformed cookie metadata in extractCookie - #7218
Open
vanshika2720 wants to merge 1 commit into
Open
Fix out-of-range panic on malformed cookie metadata in extractCookie#7218vanshika2720 wants to merge 1 commit into
vanshika2720 wants to merge 1 commit into
Conversation
Signed-off-by: Vanshika <pahalvanshikaa@gmail.com>
✅ Deploy Preview for pipecd-site canceled.
|
Contributor
Author
|
@khanhtc1202 @rahulshendre PTAL! |
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Based on that investigation, you can fill the PR template like this:
What this PR does:
Fixes a panic in
extractCookiewhen malformedCookiemetadata contains a segment without=. The change restores the bounds check removed in #6933 and adds a regression test to ensure malformed cookie input is rejected safely instead of causing the control-plane process to panic.Why we need it:
A malformed
Cookieheader can currently trigger an index-out-of-range panic before JWT authentication is completed. Since the WebAPI server runs in the same control-plane process as the PipedAPI and APIService, an unrecovered panic can terminate the entire control-plane process.This is a regression introduced by #6933.
Which issue(s) this PR fixes:
Fixes #7216
Does this PR introduce a user-facing change?: