fix(server): only redirect form posts to the Referer - #5866
Open
SulimanAbdulrazzaq wants to merge 1 commit into
Open
SulimanAbdulrazzaq wants to merge 1 commit into
SulimanAbdulrazzaq wants to merge 1 commit into
Conversation
A server function answered every successful request that accepted text/html and carried a Referer with a 302 back to that page. That Post/Redirect/Get step is meant for plain HTML form posts, but it also caught GET navigations: a link to a `#[get]` endpoint that returns a file downloaded the linking page instead, and a callback endpoint reached by a redirect was bounced back to the page it came from. Only apply the redirect to POST requests. HTML forms can only submit GET or POST, and a GET navigation should get the response itself. Refs DioxusLabs#5445, DioxusLabs#5428
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #5445. Follow-up to #5428 / #5429.
Problem
ServerFunction::make_handlerturns a successful response into302 FoundwithLocation: <Referer>whenever the request acceptstext/htmland carries aReferer. The comment says this is the Post/Redirect/Get step for a plain form post, but nothing checks the method, so it also fires on browser GET navigations:#[get]endpoint that returns a file (ByteStream) downloads the linking page instead of the file (Fullstack endpoint ByteStream response replaced by referer page data for a download link #5445);#[get]endpoint reached by a redirect is bounced back to the page it came from (point 1 of#[get]server function error responses silently converted to 302 redirect when request hasRefererheader #5428; fix(server): don't redirect error responses from #[get] server functions #5429 fixed only the error-status part).Fix
Apply the redirect only to
POSTrequests. HTML forms can only submit GET or POST, so this keeps the form-post behavior and lets a GET navigation receive the handler's response.Tests
Two unit tests in
packages/fullstack-server/src/serverfn.rssend a browser-style request (Accept: text/html,...,Referer: http://localhost:8080/page) throughmake_handler:get_navigation_returns_the_response_instead_of_redirecting_to_referer: a GET gets200and the handler's body. Before this change it gets302to the Referer.plain_form_post_still_redirects_to_referer: a POST still gets302withLocationset to the Referer.cargo test -p dioxus-server --lib --bins --tests --examples,cargo clippy -p dioxus-server --tests -- -D warningsandrustfmt --checkon the touched file pass.