]> git.ipfire.org Git - thirdparty/curl.git/commitdiff
http: fix proxy auth with blank password
authorDaniel Stenberg <daniel@haxx.se>
Fri, 26 Jun 2020 12:16:21 +0000 (14:16 +0200)
committerDaniel Stenberg <daniel@haxx.se>
Sat, 27 Jun 2020 22:29:59 +0000 (00:29 +0200)
Regression in 7.71.0

Added test case 346 to verify.

Reported-by: Kristoffer Gleditsch
Fixes #5613
Closes #5616

lib/http.c
tests/data/Makefile.inc
tests/data/test346 [new file with mode: 0644]

index 19e471ee628554886ebaf8c265ec130a7c2f913a..b914ff324ac8ad4d0d7bd9d26e96186f4e129474 100644 (file)
@@ -308,7 +308,7 @@ static CURLcode http_output_basic(struct connectdata *conn, bool proxy)
     pwd = conn->passwd;
   }
 
-  out = aprintf("%s:%s", user, pwd);
+  out = aprintf("%s:%s", user, pwd ? pwd : "");
   if(!out)
     return CURLE_OUT_OF_MEMORY;
 
index 65efdc428dbd5fb531d3c9964bfc2d5f91adb472..ef9252b703db3460fccb828cfbb1c02b2ff2d9f2 100644 (file)
@@ -58,7 +58,7 @@ test307 test308 test309 test310 test311 test312 test313 test314 test315 \
 test316 test317 test318 test319 test320 test321 test322 test323 test324 \
 test325 test326 test327 test328 test329 test330 test331 test332 test333 \
 test334 test335 test336 test337 test338 test339 test340 test341 test342 \
-test343 test344 test345 \
+test343 test344 test345 test346 \
 test350 test351 test352 test353 test354 test355 test356 test357 test358 \
 test359 \
 test393 test394 test395 \
diff --git a/tests/data/test346 b/tests/data/test346
new file mode 100644 (file)
index 0000000..6492311
--- /dev/null
@@ -0,0 +1,60 @@
+<testcase>
+<info>
+<keywords>
+HTTP
+proxy
+</keywords>
+</info>
+
+#
+# Server-side
+<reply>
+<data>
+HTTP/1.1 200 OK
+Date: Thu, 09 Nov 2010 14:49:00 GMT
+Server: test-server/fake
+Last-Modified: Tue, 13 Jun 2000 12:10:00 GMT
+ETag: "21025-dc7-39462498"
+Accept-Ranges: bytes
+Content-Length: 6
+Connection: close
+Content-Type: text/html
+Funny-head: yesyes
+
+-foo-
+</data>
+</reply>
+
+#
+# Client-side
+<client>
+<features>
+proxy
+</features>
+<server>
+http
+</server>
+<name>
+HTTP GET over proxy with credentials using blank passwords
+</name>
+<command>
+-x http://%HOSTIP:%HTTPPORT/346 -U puser: -u suser: http://remote.example/346
+</command>
+</client>
+
+#
+<verify>
+<strip>
+^User-Agent:.*
+</strip>
+<protocol>
+GET http://remote.example/346 HTTP/1.1\r
+Host: remote.example\r
+Proxy-Authorization: Basic cHVzZXI6\r
+Authorization: Basic c3VzZXI6\r
+Accept: */*\r
+Proxy-Connection: Keep-Alive\r
+\r
+</protocol>
+</verify>
+</testcase>