httpd-bugs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject DO NOT REPLY [Bug 44647] New: mod_rewrite cookie value can not contain a colon
Date Thu, 20 Mar 2008 17:47:50 GMT
https://issues.apache.org/bugzilla/show_bug.cgi?id=44647

           Summary: mod_rewrite cookie value can not contain a colon
           Product: Apache httpd-2
           Version: 2.2.8
          Platform: PC
        OS/Version: Linux
            Status: NEW
          Severity: normal
          Priority: P2
         Component: mod_rewrite
        AssignedTo: bugs@httpd.apache.org
        ReportedBy: ben.spencer@moody.edu
                CC: ben.spencer@moody.edu


The cookie value when set by mod_rewrite can not have a colon in it (directly)
or via back reference as a colon is used for the parameter delimiter. Having a
colon in the value offsets the parameter positioning.

Simple Example where cookie is ACookie=cookie_value1:cookie_value2
RewriteRule ^/ - [CO=ACookie:cookie_value1:cookie_value2:domain.com]
(cookie_value2 ends up in the domain position)

Back Reference Example where cookie is ACookie=cookie_value1:cookie_value2
RewriteCond %{HTTP_COOKIE} ACookie=(.*)
RewriteRule ^/ - [CO=CookieCopy:%1:domain.com]
(cookie_value2 ends up in the domain position)

In our environment, the back reference was attempted (with Apache functioning
as a reverse proxy to a 3rd party application) and this issue stumbled upon.


-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: bugs-unsubscribe@httpd.apache.org
For additional commands, e-mail: bugs-help@httpd.apache.org


Mime
View raw message