Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

login information should not be carried from vk to vimeo #19147

Closed
colourful-land opened this issue Feb 5, 2019 · 1 comment
Closed

login information should not be carried from vk to vimeo #19147

colourful-land opened this issue Feb 5, 2019 · 1 comment
Labels

Comments

@colourful-land
Copy link

@colourful-land colourful-land commented Feb 5, 2019

Using: 2019.01.30.1 on Ubuntu 18.04†

Reproduce the problem:

$ youtube-dl -u [username] -p [password] https://vk.com/video263838471_169844543
[vk] Downloading login page
[vk] Logging in
[vk] 263838471_169844543: Downloading webpage
[vimeo] Downloading login page
[vimeo] Logging in
ERROR: Unable to log in: bad username or password

Expected:

$ youtube-dl -u [username] -p [password] https://vk.com/video263838471_169844543
[vk] Downloading login page
[vk] Logging in
[vk] 263838471_169844543: Downloading webpage
[vimeo] 73010827: Downloading webpage
ERROR: Unable to download webpage: HTTP Error 404: Not Found (caused by HTTPError()); please 
report this issue on https://yt-dl.org/bug . Make sure you are using the latest version; type  youtube-dl - 
U  to update. Be sure to call youtube-dl with the --verbose flag and include its complete output.

As you can see, youtube-dl correctly followed the link to Vimeo, but assumed that the same username and password supplied in the commandline should be used to login to vimeo. In reality this is unlikely what the user has wanted. Given that allowing credential to be supplied for each possible redirect target (viemo) is too big a change to the commandline parameter structure, I propose not logging in at all after a redirect, to reduce the security exposure of passing a password to the site that shouldn't learn it.

(P.S. don't be distracted by vimeo reporting 404 - It's the problem of this specific test link. I couldn't find a better test link.)

† Linux 4.15.0-44-generic #47-Ubuntu SMP Mon Jan 14 11:26:59 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux

@dstftw dstftw closed this Feb 5, 2019
@dstftw dstftw added the duplicate label Feb 5, 2019
@dstftw
Copy link
Collaborator

@dstftw dstftw commented Feb 5, 2019

Duplicate of #9254.

@ytdl-org ytdl-org deleted a comment from colourful-land Feb 5, 2019
@ytdl-org ytdl-org locked and limited conversation to collaborators Feb 5, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants
You can’t perform that action at this time.