hc-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject DO NOT REPLY [Bug 36918] - Digest auth uses wrong uri in proxy authentication
Date Tue, 04 Oct 2005 22:48:42 GMT
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG·
RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT
<http://issues.apache.org/bugzilla/show_bug.cgi?id=36918>.
ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND·
INSERTED IN THE BUG DATABASE.

http://issues.apache.org/bugzilla/show_bug.cgi?id=36918





------- Additional Comments From ender3rd@gmail.com  2005-10-05 00:48 -------
(In reply to comment #3)
> Owen,
> Can you also capture the content of the Digest response generated by Firefox for
> non-SSL (non-tunneled) connections ? I wonder if the digest-uri value would be
> something like "http://www.yahoo.com:80/stuff" or like "/stuff"
> 
> Meanwhile, we'll be thinking of a workaround for the 3.0 release that does not
> require API changes. The proper fix for this problem most likely will have to
> wait until 3.1 or even 4.0
> 
> Oleg

Oleg,
See below for similar headers for a non-SSL connection.  It's like "/stuff"
though I'm not sure if that is strictly RFC compliant or not.  Tommorrow I'll
try a few variations and see if anything interesting happens.

from firefox:
GET http://www.google.com/search?q=combrio HTTP/1.1
Proxy-Authorization: Digest username="proxytest", realm="Digest",
nonce="9ead1d6748c8c5015ad4977b92780d2d2bf1ce754d79f240533feaf1a90b59badf7027bba74334a7",
uri="/search?q=combrio", algorithm=MD5-sess,
response="42ad6a4571edb21780c26827a0c3910e",
opaque="9c55241868ffb3f34487f1a72519110a", qop=auth, nc=00000001,
cnonce="2e4b57bad694b520"

Owen

-- 
Configure bugmail: http://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

---------------------------------------------------------------------
To unsubscribe, e-mail: httpclient-dev-unsubscribe@jakarta.apache.org
For additional commands, e-mail: httpclient-dev-help@jakarta.apache.org


Mime
View raw message