fix(netty): preserve QUERY across redirects - #2317
Conversation
|
We use ahc in https://github.com/playframework/play-ws and I am in the process of upgrading to v3 - and found some thing worth adressing. |
This comment was marked as outdated.
This comment was marked as outdated.
b8c4db4 to
4596aa0
Compare
This comment was marked as outdated.
This comment was marked as outdated.
|
@hyperxpro I have addressed all concrete review feedback in five follow-up commits and rerun Two policy decisions remain:
Please let me know which scope you prefer and whether retaining the existing cross-origin policy is acceptable here. |
69393b5 to
0a6b003
Compare
|
Since I can no longer reply inline after the force-push:
Thanks for clarifying, and for taking the general follow-up issue. I kept AHC's existing cross-origin keep-body trust model unchanged in this PR. The branch is now rebased onto latest
Agreed. I kept this PR narrowly scoped to QUERY; the existing PUT, PATCH, and DELETE behavior remains unchanged and is pinned by regression tests. The broader POST-only rewrite remains a separate follow-up. Also corrected: #2316 landed the replay preservation through The branch is now rebased onto latest |
RFC 10008 requires QUERY requests to retain their method and content across 301, 302, 307, and 308 redirects. AHC treated QUERY like POST on 301 and non-strict 302, changing it to GET and dropping its content. Preserve QUERY while keeping established behavior for other methods. Add the standardized method constant and regression coverage for every redirect status, strict 302, repeatable and non-repeatable bodies, and cross-origin credential stripping. Cross-origin QUERY redirects retain AHC's existing keep-body trust model. A broader change limiting legacy redirect rewrites to POST remains a separate compatibility decision. OpenAI Codex on behalf of Matthias Kurz. Co-Authored-By: OpenAI Codex <codex@openai.com>
0a6b003 to
94bacf1
Compare
|
Thanks a lot! |
Summary
HttpConstants.Methods.QUERYconstant and name the redirect-policy decisions explicitly.Problem
Redirect30xInterceptortreated every method other than GET, HEAD, and OPTIONS like POST when handling 301 and non-strict 302 responses. As a result, a QUERY request was changed to GET and its query content and Content-Type were dropped.RFC 10008 section 2.5 explicitly says that the POST-to-GET exceptions for 301 and 302 do not apply to QUERY. A QUERY request must instead be repeated with its content for 301, 302, 307, and 308. Only a 303 response calls for a GET request to the redirect target.
Change
Recognize QUERY in the redirect policy so 301 and 302 retain the original method and body. The existing 307, 308, 303, HEAD, OPTIONS, and POST behavior is unchanged. The implementation uses named decisions rather than embedding the QUERY exception in one compound expression.
Cross-origin QUERY redirects retain their method, content, and Content-Type, as required to repeat the query. This means a QUERY body now crosses origins on 301 and 302 where the old, incorrect GET rewrite dropped it. AHC already uses that body-replay trust model for 307 and 308. Existing redirect security still strips Authorization, Realm credentials, and user-supplied Cookie headers before sending the request to the new origin. A separate, representation-independent policy that refuses cross-origin keep-body redirects could be considered, but this conformance fix does not currently add one.
The broader pre-existing behavior that converts PUT, PATCH, DELETE, and other methods to GET after 301 and non-strict 302 responses is deliberately out of scope. It changes established behavior for existing users and is handled in a separate follow-up branch,
fix/non-post-redirects.That follow-up handles QUERY as an ordinary non-POST method and therefore supersedes this pull request's QUERY-specific interceptor condition if both land. Keeping this narrow pull request separate still allows the standardized QUERY behavior to land even if the broader compatibility change is rejected; the public method constant and QUERY-specific regression coverage remain useful either way.
This adds the public
HttpConstants.Methods.QUERYstring constant. It is an additive, user-facing API for constructing QUERY requests; there is no incompatible API change.AI disclosure
OpenAI Codex on behalf of Matthias Kurz. The commits include
Co-Authored-By: OpenAI Codex <codex@openai.com>perAGENTS.md.Test plan
./mvnw -pl client -Dtest=RedirectBodyTest#query301KeepsMethodAndBody test../mvnw -pl client -Dtest=RedirectBodyTest teston JDK 11../mvnw -pl client -Dtest=RedirectBodyTest,RedirectCredentialSecurityTest teston JDK 11: 57 tests passed../mvnw clean verifyon JDK 11: BUILD SUCCESS (full reactor, including tests, Javadocs, artifact signing, coverage, and Revapi).Generated with OpenAI Codex.