Skip to content

keep method and digest-uri in A2 for qop=auth-int#2269

Open
madib06ops wants to merge 1 commit into
AsyncHttpClient:mainfrom
madib06ops:digest-auth-int-a2
Open

keep method and digest-uri in A2 for qop=auth-int#2269
madib06ops wants to merge 1 commit into
AsyncHttpClient:mainfrom
madib06ops:digest-auth-int-a2

Conversation

@madib06ops

Copy link
Copy Markdown
Contributor

Realm.Builder.ha2 writes A2 into the recycled StringBuilder that newResponse took from StringBuilderPool, but on the auth-int branch with no precomputed entity-body hash it calls toHexString, which takes that same thread-local builder and resets it, so the "POST:/secret:" already written is discarded. A2 comes out as the empty-body hash twice and the Digest response no longer binds the request method or the target URI. A server reaches this by answering with qop="auth-int" in WWW-Authenticate or Proxy-Authenticate, since parseRawQop picks auth-int when that is the only value offered.

Appending with appendBase16 keeps the hash in the buffer already being built, which is what newResponse does for HA1 and HA2 a few lines below. The added RealmTest case checks the response against the RFC 7616 A2 and fails on the current code.

hyperxpro pushed a commit that referenced this pull request Jul 23, 2026
## Summary

- pass the auth-int entity-body hash to the request-specific
`Realm.Builder`
- build the preemptive Digest realm once for origin and proxy
authentication
- remove the duplicate digest-response implementation that was
recalculating HA1 and whose result was overwritten by the final build
- verify the emitted origin and proxy responses against an independent
MD5 calculation

This follows the entity-body-hash flow already used by the 401 and 407
interceptors. It does not modify `Realm.java`, so it remains compatible
with #2269.

## Verification

- `./mvnw -pl client
-Dtest=org.asynchttpclient.util.AuthenticatorUtilsTest,org.asynchttpclient.RealmTest,org.asynchttpclient.DigestAuthTest,org.asynchttpclient.DigestAuthRfc7616Test
test` (53 tests passed)
- `./mvnw -B -ntp -pl client -DskipTests -Dmaven.javadoc.skip=true
-Dgpg.skip=true verify` (Revapi passed)

The full JDK 11 `./mvnw clean verify` gate was not run because this
environment provides JDK 21 only.

Codex on behalf of Pavel Ptashyts

Co-authored-by: Codex <codex@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant