Conversation
Member
Author
|
@pratt4 - Finally rolling :) |
hyperxpro
pushed a commit
that referenced
this pull request
Jul 25, 2026
Realm.Builder.ha2 writes A2 into the recycled StringBuilder that newResponse took from StringBuilderPool, but on the auth-int branch with no precomputed entity-body hash it called StringUtils.toHexString, which takes that same thread-local builder and resets it. The "POST:/secret:" already written was discarded and A2 came out as the empty-body hash twice, so the Digest response no longer bound the request method or the target URI. Appending with appendBase16 keeps the hash in the buffer already being built, which is what ha1 and newResponse already do for HA1 and HA2. The two encoders emit identical lowercase, zero-padded hex, so the digest is unchanged everywhere the branch was already correct. Latent since #2148 replaced the EMPTY_ENTITY_MD5 constant with a computed hash. The null-entityBodyHash branch is no longer reachable from the request pipeline: #2276 wired setEntityBodyHash into perRequestAuthorizationHeader and computeBodyHash never returns null, so no wrong header reaches the wire today. It is still reached by the nextnonce rotation in Interceptors and by Realms built through the public API. The added RealmTest case checks the response against the RFC 7616 A2 and fails on the current code.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation:
Achieve full RFC 7616 compliance for HTTP Digest Authentication — supporting stale nonce recovery, nonce count tracking, userhash, Authentication-Info processing, multiple challenge negotiation, algorithm-aware auth-int, and Proxy-Authenticate parity.
Modification:
Result:
Fixes #2068