From 005b079e2d14fa21fc6fd7a2a3ba528271afde3d Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 1 Aug 2026 22:46:45 -1000 Subject: Fix cookie name escaping and stored hash trimming --- custom/extensions/auth-inline.lua | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) (limited to 'custom/extensions/auth-inline.lua') diff --git a/custom/extensions/auth-inline.lua b/custom/extensions/auth-inline.lua index 168a444..0cd9da9 100644 --- a/custom/extensions/auth-inline.lua +++ b/custom/extensions/auth-inline.lua @@ -206,13 +206,22 @@ function parse_qs(qs) return tab end +-- Escape the Lua pattern magic characters, so a name is matched literally. +local function pattern_escape(s) + return (string.gsub(s, "([%^%$%(%)%%%.%[%]%*%+%-%?])", "%%%1")) +end + -- Return the value of the named cookie, or nil. The stored token was already -- url-encoded by secure_value, so it is returned verbatim, which keeps the -- write path (set_cookie) and the read path symmetric. Decoding it here would -- break the signature check for any value carrying a percent escape. +-- +-- The name is escaped because it lands in a pattern. A cookie_name holding a +-- magic character, say "cgit-auth", would otherwise read as a pattern and stop +-- matching its own cookie while matching names nobody configured. function get_cookie(cookies, name) cookies = string.gsub(";" .. (cookies or "") .. ";", "%s*;%s*", ";") - return string.match(cookies, ";" .. name .. "=(.-);") + return string.match(cookies, ";" .. pattern_escape(name) .. "=(.-);") end function tohex(b) -- cgit v2.8.0