]> git.ipfire.org Git - thirdparty/asterisk.git/commitdiff
Tolerate presence of RFC2965 Cookie2 header by ignoring it
authorMatthew Jordan <mjordan@digium.com>
Sun, 21 Jul 2013 03:09:59 +0000 (03:09 +0000)
committerMatthew Jordan <mjordan@digium.com>
Sun, 21 Jul 2013 03:09:59 +0000 (03:09 +0000)
This patch modifies parsing of cookies in Asterisk's http server by doing an
explicit comparison of the "Cookie" header instead of looking at the first
6 characters to determine if the header is a cookie header. This avoids
parsing "Cookie2" headers and overwriting the previously parsed "Cookie"
header.

Note that we probably should be appending the cookies in each "Cookie"
header to the parsed results; however, while clients can send multiple
cookie headers they never really do. While this patch doesn't improve
Asterisk's behavior in that regard, it shouldn't make it any worse either.

Note that the solution in this patch was pointed out on the issue by the
issue reporter, Stuart Henderson.

(closes issue ASTERISK-21789)
Reported by: Stuart Henderson
Tested by: mjordan, Stuart Henderson
........

Merged revisions 394899 from http://svn.asterisk.org/svn/asterisk/branches/1.8

git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/11@394900 65c4cc65-6c06-0410-ace0-fbb531ad65f3

main/http.c

index 565c41f8e099cf1c9a4413118dc669656db82a2b..3f69a025c6b5fcc1582c73525300b19b16a7c336 100644 (file)
@@ -666,7 +666,7 @@ struct ast_variable *ast_http_get_post_vars(
                        prev = v;
                }
        }
-       
+
 done:
        ast_free(buf);
        return post_vars;
@@ -843,7 +843,7 @@ struct ast_variable *ast_http_get_cookies(struct ast_variable *headers)
        struct ast_variable *v, *cookies=NULL;
 
        for (v = headers; v; v = v->next) {
-               if (!strncasecmp(v->name, "Cookie", 6)) {
+               if (!strcasecmp(v->name, "Cookie")) {
                        char *tmp = ast_strdupa(v->value);
                        if (cookies) {
                                ast_variables_destroy(cookies);