Skip to content

Unvalidated Redirect Case09 use configured host#8

Merged
thc202 merged 1 commit into
zaproxy:mainfrom
kingthorin:redir-case09-fix
Sep 2, 2025
Merged

Unvalidated Redirect Case09 use configured host#8
thc202 merged 1 commit into
zaproxy:mainfrom
kingthorin:redir-case09-fix

Conversation

@kingthorin
Copy link
Copy Markdown
Member

Unvalidated-Redirect/Redirect-FalsePositives-GET/Case09... now uses the first configured host name (identified via JMX) instead of the requested host name (which would have been from a manipulated Host header).

I've changed the code only for that specific case as I wasn't sure of the impact(s) elsewhere in wavsep.

@kingthorin kingthorin force-pushed the redir-case09-fix branch 5 times, most recently from d9151a8 to 5814ffc Compare August 26, 2025 13:40
@kingthorin
Copy link
Copy Markdown
Member Author

I'm not sure why it's showing end of file changes. I think it's a GitHub UI issue. Copilot claims it's just line number changes and there's no actual content change..... 🤷‍♂️ (If you Hide Whitespace then they're ignored.)

@psiinon
Copy link
Copy Markdown
Member

psiinon commented Aug 27, 2025

Has conflicts

@kingthorin
Copy link
Copy Markdown
Member Author

Hopefully that's better

@thc202
Copy link
Copy Markdown
Member

thc202 commented Aug 28, 2025

The conflict was addressed but no other comments.

@kingthorin
Copy link
Copy Markdown
Member Author

The formatting/alignment was adjusted, and the commented code removed and explanation comment revised.

@kingthorin
Copy link
Copy Markdown
Member Author

Ugh, broken with a reset along the way.....fix coming

@kingthorin
Copy link
Copy Markdown
Member Author

I'm leaving it conflicting for the time being until leading white space is actually addressed, #10 didn't get it all.

@psiinon
Copy link
Copy Markdown
Member

psiinon commented Aug 28, 2025

I'm not planning on making any more whitespace changes for now. But I have some other changes needed for #11 ...

@kingthorin
Copy link
Copy Markdown
Member Author

So should I be using just spaces for changed lines or should I be maintaining whatever weird mix?

@psiinon
Copy link
Copy Markdown
Member

psiinon commented Aug 28, 2025

Ideally spaces at the start of all lines, although if its one of the files that wasnt changed then whatever looks good?

@kingthorin
Copy link
Copy Markdown
Member Author

Okay, hopefully this works for now and can get in before the next conflict 😀

Comment thread CHANGELOG.md Outdated
@kingthorin
Copy link
Copy Markdown
Member Author

Hopefully got both those.

@kingthorin kingthorin force-pushed the redir-case09-fix branch 5 times, most recently from 6075c8c to 4b11b28 Compare August 28, 2025 14:57
@kingthorin kingthorin force-pushed the redir-case09-fix branch 4 times, most recently from afce8ad to 7f27c87 Compare August 29, 2025 14:32
@thc202
Copy link
Copy Markdown
Member

thc202 commented Sep 2, 2025

lgtm but the changelog could be updated.

Signed-off-by: kingthorin <kingthorin@users.noreply.github.com>

# Conflicts:
#	CHANGELOG.md
@kingthorin
Copy link
Copy Markdown
Member Author

CHANGELOG updated.

@thc202 thc202 merged commit 1776843 into zaproxy:main Sep 2, 2025
1 check passed
@thc202
Copy link
Copy Markdown
Member

thc202 commented Sep 2, 2025

Thank you!

@kingthorin kingthorin deleted the redir-case09-fix branch September 2, 2025 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants