Feature #3719

Feature #859: open-uri doesn't allow redirection to https

open-uri should allow redirects from http to https

Added by Hans de Graaff over 3 years ago. Updated about 1 year ago.

[ruby-core:31771]
Status:Assigned
Priority:Normal
Assignee:Akira Tanaka
Category:lib
Target version:next minor

Description

=begin
Currently open-uri does not allow redirects from http to https. http://redmine.ruby-lang.org/repositories/revision/1?rev=21381 reverts the ability to redirect between http and https with a note that this may compromise security, but as far as I can tell this is only true for https -> http redirects. Redirecting from http -> https should not pose such security problems and could still be allowed. This can be accomplished by allowing https for the destination URL, but not for the source URL:

  • def OpenURI.redirectable?(uri1, uri2) # :nodoc:
  • # This test is intended to forbid a redirection from http://... to
  • # file:///etc/passwd.
  • # However this is ad hoc. It should be extensible/configurable.
  • uri1.scheme.downcase == uri2.scheme.downcase ||
  • (/\A(?:http|ftp)\z/i =~ uri1.scheme && /\A(?:https?|ftp)\z/i =~ uri2.scheme)
  • end

    I'm seeing this issue with ruby 1.8.7 but the code for ruby 1.9.2 is the same.
    =end

History

#1 Updated by Shyouhei Urabe over 3 years ago

  • Status changed from Open to Assigned
  • Assignee set to Akira Tanaka

=begin

=end

#2 Updated by Joseph Holsten almost 3 years ago

=begin
I'm still seeing this issue. I like the way this patch works, allowing redirection from http to https but not the other way.

What needs to happen for this to be applied?
=end

#3 Updated by Yusuke Endoh over 1 year ago

  • Description updated (diff)
  • Target version set to next minor

#4 Updated by Akira Tanaka about 1 year ago

  • Parent task set to #859

Also available in: Atom PDF