go/src
Damien Neil 7c84234142 net/http/httputil: avoid query parameter smuggling
Query parameter smuggling occurs when a proxy's interpretation
of query parameters differs from that of a downstream server.
Change ReverseProxy to avoid forwarding ignored query parameters.

Remove unparsable query parameters from the outbound request

   * if req.Form != nil after calling ReverseProxy.Director; and
   * before calling ReverseProxy.Rewrite.

This change preserves the existing behavior of forwarding the
raw query untouched if a Director hook does not parse the query
by calling Request.ParseForm (possibly indirectly).

Fixes #54663
Fixes CVE-2022-2880

Change-Id: If1621f6b0e73a49d79059dae9e6b256e0ff18ca9
Reviewed-on: https://go-review.googlesource.com/c/go/+/432976
Reviewed-by: Roland Shoemaker <roland@golang.org>
Reviewed-by: Brad Fitzpatrick <bradfitz@golang.org>
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Damien Neil <dneil@google.com>
2022-09-23 21:06:17 +00:00
..
archive
bufio
builtin
bytes bytes, strings: add ASCII fast path to EqualFold 2022-09-21 14:00:37 +00:00
cmd cmd/compile: use "init... cycle" instead of "init... loop" in error messages 2022-09-23 20:27:09 +00:00
compress compress/flate: update NewReader documentation 2022-09-15 20:02:32 +00:00
container
context
crypto crypto/tls: convert Conn.activeCall to atomic type 2022-09-22 18:24:49 +00:00
database/sql database: convert DB.{waitDuration,numClosed} to atomic type 2022-09-15 21:11:10 +00:00
debug debug/elf: validate shstrndx 2022-09-19 17:01:22 +00:00
embed
encoding
errors
expvar
flag flag: test IsBoolFlag when creating the usage message 2022-09-19 21:54:35 +00:00
fmt fmt: rely on utf8.AppendRune 2022-09-21 13:54:31 +00:00
go cmd/compile: handle go.mod error msg reference in noder, not type checker 2022-09-23 20:27:07 +00:00
hash hash/crc32: remove redundant code 2022-09-15 21:07:21 +00:00
html
image
index/suffixarray
internal all: replace package ioutil with os and io in src 2022-09-20 02:13:02 +00:00
io
log
math math: show value of integer constants in comments 2022-09-21 14:07:39 +00:00
mime mime/multipart: use %w when wrapping error in NextPart 2022-09-20 02:11:38 +00:00
net net/http/httputil: avoid query parameter smuggling 2022-09-23 21:06:17 +00:00
os os: use wait6 to avoid wait/kill race on netbsd 2022-09-19 18:44:37 +00:00
path path/filepath: optimize isReservedName 2022-09-23 04:34:52 +00:00
plugin
reflect reflect: rtype.MethodByName using binary search 2022-09-19 17:55:13 +00:00
regexp
runtime runtime/pprof: force use of 4-column profiles in pprof memprofile output 2022-09-23 01:07:03 +00:00
sort
strconv strconv: add a test case when base is illegal 2022-09-15 21:09:39 +00:00
strings bytes, strings: add ASCII fast path to EqualFold 2022-09-21 14:00:37 +00:00
sync cmd/compile,sync: make accessing address of zero offset struct field inline cost 0 2022-09-19 02:45:26 +00:00
syscall syscall: drop compatibility for FreeBSD < 10.0 2022-09-20 15:46:41 +00:00
testdata
testing testing: allow go test -run=^$ testing 2022-09-16 16:21:38 +00:00
text text/template/parse: fix confusion about markers near right delims 2022-09-23 15:03:43 +00:00
time time: optimize Parse for []byte arguments 2022-09-20 16:21:31 +00:00
unicode
unsafe
vendor all: update vendored golang.org/x/net 2022-09-21 15:07:53 +00:00
Make.dist
README.vendor
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod all: update vendored golang.org/x/net 2022-09-21 15:07:53 +00:00
go.sum all: tidy std module 2022-09-21 20:59:10 +00:00
make.bash
make.bat
make.rc
race.bash
race.bat
run.bash
run.bat
run.rc

README.vendor

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.