Skip to content

Strip credentials on cross-origin HTTP redirects - #6771

Merged
tim-smart merged 1 commit into
mainfrom
agent/codex-engineer/0bc27f9f
Jul 30, 2026
Merged

Strip credentials on cross-origin HTTP redirects#6771
tim-smart merged 1 commit into
mainfrom
agent/codex-engineer/0bc27f9f

Conversation

@tim-smart

Copy link
Copy Markdown
Contributor

Summary

  • strip Authorization, Proxy-Authorization, and Cookie headers before following cross-origin redirects
  • align 301, 302, and 303 method and body handling with fetch and undici
  • cover same-origin, cross-origin, scheme-downgrade, relative, and method rewrite behavior

Security rationale

A redirect target can be controlled by a different origin and must not receive credentials intended for the original origin. Comparing URL origins on every hop prevents authorization and cookie values from being replayed to another scheme, host, or port while retaining them for same-origin redirects.

Cookie Ref domain and path scoping is intentionally left out of this focused patch. Existing cookie headers are stripped before a cross-origin hop, and the redirect loop does not re-run cookie-jar preprocessing between hops.

Validation

  • pnpm lint-fix
  • pnpm --filter effect test --run test/unstable/http/HttpClient.test.ts
  • pnpm check

Closes EFF-216

@github-project-automation github-project-automation Bot moved this to Discussion Ongoing in PR Backlog Jul 30, 2026
@changeset-bot

changeset-bot Bot commented Jul 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: af3afc3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 29 packages
Name Type
effect Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node-shared Patch
@effect/platform-node Patch
@effect/vitest Patch
@effect/ai-anthropic Patch
@effect/ai-openai-compat Patch
@effect/ai-openai Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/docgen Patch
@effect/openapi-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Jul 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 6.63 KB 6.63 KB 0.00 KB (0.00%)
batching.ts 9.42 KB 9.42 KB 0.00 KB (0.00%)
brand.ts 6.31 KB 6.31 KB 0.00 KB (0.00%)
cache.ts 10.12 KB 10.12 KB 0.00 KB (0.00%)
config.ts 19.90 KB 19.90 KB 0.00 KB (0.00%)
differ.ts 20.03 KB 20.03 KB 0.00 KB (0.00%)
http-client.ts 20.94 KB 20.94 KB -0.00 KB (-0.01%)
logger.ts 10.28 KB 10.28 KB 0.00 KB (0.00%)
metric.ts 8.55 KB 8.55 KB 0.00 KB (0.00%)
optic.ts 7.33 KB 7.33 KB 0.00 KB (0.00%)
pubsub.ts 14.26 KB 14.26 KB 0.00 KB (0.00%)
queue.ts 11.09 KB 11.09 KB 0.00 KB (0.00%)
schedule.ts 10.27 KB 10.27 KB 0.00 KB (0.00%)
schema-class.ts 18.86 KB 18.86 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.78 KB 28.78 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.09 KB 25.09 KB 0.00 KB (0.00%)
schema-string-transformation.ts 12.95 KB 12.95 KB 0.00 KB (0.00%)
schema-string.ts 10.65 KB 10.65 KB 0.00 KB (0.00%)
schema-template-literal.ts 14.85 KB 14.85 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.66 KB 21.66 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.10 KB 24.10 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.00 KB 19.00 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 18.73 KB 18.73 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.59 KB 18.59 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.23 KB 22.23 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.27 KB 19.27 KB 0.00 KB (0.00%)
schema.ts 18.12 KB 18.12 KB 0.00 KB (0.00%)
stm.ts 12.05 KB 12.05 KB 0.00 KB (0.00%)
stream.ts 9.37 KB 9.37 KB 0.00 KB (0.00%)

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ One minor suggestion inline — otherwise solid.

Reviewed changes

  • Credential stripping on cross-origin redirects: strips Authorization, Proxy-Authorization, and Cookie headers before following a redirect to a different origin (including scheme downgrades), preventing credential replay
  • Method/body rewriting for 301, 302, and 303: aligns redirect behavior with the fetch spec — POST rewrites to GET for 301/302, any non-GET/HEAD rewrites to GET for 303, with body cleared
  • Comprehensive test coverage: 7 new test cases covering same-origin, cross-origin, scheme downgrade, relative Location resolution, and all method rewrite combinations

Note: 1 inline comment(s) dropped because they did not anchor to lines inside the PR diff:

  • packages/effect/src/unstable/http/HttpClient.ts:1455 (RIGHT) — line 1455 (RIGHT) is not inside a diff hunk

Pullfrog  | Fix it ➔View workflow run | Using DeepSeek Pro (free via Pullfrog for OSS) (Kimi K2 not used — the program covers this model; add its provider key to run your pick) | 𝕏

@tim-smart
tim-smart merged commit 660875b into main Jul 30, 2026
16 checks passed
@tim-smart
tim-smart deleted the agent/codex-engineer/0bc27f9f branch July 30, 2026 02:34
@github-project-automation github-project-automation Bot moved this from Discussion Ongoing to Done in PR Backlog Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 bug Something isn't working

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant