-
Notifications
You must be signed in to change notification settings - Fork 50
fix(security): remove proxy and cookie auth headers on insecure redirect #653
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 2 commits
Commits
Show all changes
26 commits
Select commit
Hold shift + click to select a range
e6a2654
fix: remove proxy and cookie auth headers on insecure redirect
MIchaelMainer fa48454
fix: dispose of HttpRequestMessage instance
MIchaelMainer a883463
test: update tests to dispose HttpRequestMessage
MIchaelMainer 652569a
Merge branch 'main' into mmainer/redirect-sec
ramsessanchez 088f69f
fix<security): remove ProxyAuthorization header if the new URL doesn'…
MIchaelMainer 7e8e746
fix(security): enable configuration to allow removing arbitrary heade…
MIchaelMainer 9ca26d6
test(redirecthandlertests): use a more concise statement
MIchaelMainer c066d52
test: fix using directive order
MIchaelMainer ee6e404
Merge branch 'mmainer/redirect-sec' of https://github.com/microsoft/k…
MIchaelMainer 7a89dc0
Merge branch 'main' into mmainer/redirect-sec
adrian05-ms 0bba6b4
Fixing linter errors
adrian05-ms 6de56eb
Testing fix for build error
adrian05-ms 6336c5a
Merge branch 'main' into mmainer/redirect-sec
adrian05-ms 075bb15
code review changes
adrian05-ms 399e49c
linting: use where when possible
baywet c1ea4bc
changing approach on removing sensitive headers
adrian05-ms 588b9c6
Fixing format and test coverage
adrian05-ms afaadca
sonar code suggestions
adrian05-ms 9677a7e
fix(security): add customizable callback to allow removing headers on…
MIchaelMainer 746a846
fix(security): add customizable callback to remove headers on redirect
MIchaelMainer 1f7b2cb
test: validate removing headers on redirect
MIchaelMainer cb728ed
chore: fix whitespace
MIchaelMainer c16b97f
chore: make web proxy static
MIchaelMainer 21755df
chore: make proxy resolver static
MIchaelMainer b70eb92
Update src/http/httpClient/Middleware/RedirectHandler.cs
adrian05-ms c845bdd
reverting back static change
adrian05-ms File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.