fixed Host header vulnerability #1196

This commit is contained in:
mdipierro
2016-03-21 01:15:46 -05:00
parent d1094e7b0c
commit bd6115ad62
4 changed files with 26 additions and 6 deletions
+2 -1
View File
@@ -58,7 +58,8 @@ response.form_label_separator = myconf.get('forms.separator') or ''
from gluon.tools import Auth, Service, PluginManager from gluon.tools import Auth, Service, PluginManager
auth = Auth(db, host=myconf.get('host.name')) # host names must be a list of allowed host names (glob syntax allowed)
auth = Auth(db, host_names=myconf.get('host.names'))
service = Service() service = Service()
plugins = PluginManager() plugins = PluginManager()
+1 -1
View File
@@ -8,7 +8,7 @@ generator = Web2py Web Framework
; Host configuration ; Host configuration
[host] [host]
name = localhost names = localhost:*, 127.0.0.1:*, *:*, *
; db configuration ; db configuration
[db] [db]
+2 -2
View File
@@ -69,8 +69,8 @@ class AppConfigDict(dict):
return False return False
elif value.isdigit() or (value[0]=='-' and value[1:].isdigit()): elif value.isdigit() or (value[0]=='-' and value[1:].isdigit()):
return int(value) return int(value)
elif ', ' in value: elif ',' in value:
return value.split(', ') return map(lambda x:x.strip(),value.split(','))
else: else:
try: try:
return float(value) return float(value)
+21 -2
View File
@@ -23,6 +23,7 @@ import glob
import os import os
import re import re
import time import time
import fnmatch
import traceback import traceback
import smtplib import smtplib
import urllib import urllib
@@ -1717,11 +1718,29 @@ class Auth(object):
def here(self): def here(self):
return URL(args=current.request.args, vars=current.request.get_vars) return URL(args=current.request.args, vars=current.request.get_vars)
def select_host(self, host, host_names=None):
"""
checks that host is valid, i.e. in the list of glob host_names
if the host is missing, then is it selects the first entry from host_names
read more here: https://github.com/web2py/web2py/issues/1196
"""
if host:
if host_names:
for item in host_names:
if fnmatch.fnmatch(host, item):
break
else:
raise HTTP(403, "Invalid Hostname")
elif host_names:
host = host_names[0]
else:
host = 'localhost'
def __init__(self, environment=None, db=None, mailer=True, def __init__(self, environment=None, db=None, mailer=True,
hmac_key=None, controller='default', function='user', hmac_key=None, controller='default', function='user',
cas_provider=None, signature=True, secure=False, cas_provider=None, signature=True, secure=False,
csrf_prevention=True, propagate_extension=None, csrf_prevention=True, propagate_extension=None,
url_index=None, jwt=None, host=None): url_index=None, jwt=None, host_names=None):
## next two lines for backward compatibility ## next two lines for backward compatibility
if not db and environment and isinstance(environment, DAL): if not db and environment and isinstance(environment, DAL):
@@ -1765,7 +1784,7 @@ class Auth(object):
settings = self.settings = Settings() settings = self.settings = Settings()
settings.update(Auth.default_settings) settings.update(Auth.default_settings)
host = host or request.env.http_host host = self.select_host(request.env.http_host, host_names)
settings.update( settings.update(
cas_domains=[host], cas_domains=[host],
enable_tokens=False, enable_tokens=False,