|
37 | 37 | SSLError, |
38 | 38 | ) |
39 | 39 | from urllib3.poolmanager import ProxyManager, proxy_from_url |
| 40 | +from urllib3.util.retry import RequestHistory |
40 | 41 | from urllib3.util.ssl_ import create_urllib3_context |
41 | 42 | from urllib3.util.timeout import Timeout |
42 | 43 |
|
@@ -300,6 +301,77 @@ def test_cross_host_redirect(self) -> None: |
300 | 301 | assert r._pool is not None |
301 | 302 | assert r._pool.host != self.http_host_alt |
302 | 303 |
|
| 304 | + _sensitive_headers = { |
| 305 | + "Authorization": "foo", |
| 306 | + "Proxy-Authorization": "bar", |
| 307 | + "Cookie": "foo=bar", |
| 308 | + } |
| 309 | + |
| 310 | + @pytest.mark.parametrize( |
| 311 | + "sensitive_headers", |
| 312 | + (_sensitive_headers, {k.lower(): v for k, v in _sensitive_headers.items()}), |
| 313 | + ids=("capitalized", "lowercase"), |
| 314 | + ) |
| 315 | + def test_cross_host_redirect_remove_headers_via_proxy_manager( |
| 316 | + self, sensitive_headers: dict[str, str] |
| 317 | + ) -> None: |
| 318 | + headers_url = f"{self.http_url_alt}/headers" |
| 319 | + initial_url = f"{self.http_url}/redirect?target={headers_url}" |
| 320 | + with proxy_from_url(self.proxy_url) as proxy_mgr: |
| 321 | + r = proxy_mgr.request( |
| 322 | + "GET", initial_url, headers=sensitive_headers, retries=1 |
| 323 | + ) |
| 324 | + assert r.status == 200 |
| 325 | + assert r.retries is not None |
| 326 | + assert r.retries.history == ( |
| 327 | + RequestHistory( |
| 328 | + method="GET", |
| 329 | + url=initial_url, |
| 330 | + error=None, |
| 331 | + status=303, |
| 332 | + redirect_location=headers_url, |
| 333 | + ), |
| 334 | + ) |
| 335 | + data = r.json() |
| 336 | + for header in sensitive_headers: |
| 337 | + assert header not in data |
| 338 | + |
| 339 | + @pytest.mark.parametrize( |
| 340 | + "sensitive_headers", |
| 341 | + (_sensitive_headers, {k.lower(): v for k, v in _sensitive_headers.items()}), |
| 342 | + ids=("capitalized", "lowercase"), |
| 343 | + ) |
| 344 | + def test_cross_host_redirect_remove_headers_via_pool( |
| 345 | + self, sensitive_headers: dict[str, str] |
| 346 | + ) -> None: |
| 347 | + headers_url = f"{self.http_url_alt}/headers" |
| 348 | + initial_url = f"{self.http_url}/redirect?target={headers_url}" |
| 349 | + with proxy_from_url(self.proxy_url) as proxy_mgr: |
| 350 | + pool = proxy_mgr.connection_from_url(self.http_url) |
| 351 | + r = pool.urlopen( |
| 352 | + "GET", |
| 353 | + initial_url, |
| 354 | + headers=sensitive_headers, |
| 355 | + retries=1, |
| 356 | + redirect=True, |
| 357 | + assert_same_host=False, |
| 358 | + preload_content=True, |
| 359 | + ) |
| 360 | + assert r.status == 200 |
| 361 | + assert r.retries is not None |
| 362 | + assert r.retries.history == ( |
| 363 | + RequestHistory( |
| 364 | + method="GET", |
| 365 | + url=initial_url, |
| 366 | + error=None, |
| 367 | + status=303, |
| 368 | + redirect_location=headers_url, |
| 369 | + ), |
| 370 | + ) |
| 371 | + data = r.json() |
| 372 | + for header in sensitive_headers: |
| 373 | + assert header not in data |
| 374 | + |
303 | 375 | def test_cross_protocol_redirect(self) -> None: |
304 | 376 | with proxy_from_url(self.proxy_url, ca_certs=DEFAULT_CA) as http: |
305 | 377 | cross_protocol_location = f"{self.https_url}/echo?a=b" |
|
0 commit comments