Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-4141

Crowd OpenID server v2 login does not work when I have a cookie with a comma in its value

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Low
    • 2.8.2
    • None
    • OpenID
    • None

    Description

      Cookie causing issues:

      mt.pevt=mr%3Dt1415380136%26mi%3D'2.2126138620.1401348482803'%26u%3D'https://www.atlassian.com/software/jira/try/'%26e%3D!(xi)%26ii%3D!('2,2,7904,,1416204185,2,1416204189')%26eoq%3D!t

      cURL command to reproduce the behaviour:

      curl -I -X GET 'https://id.atlassian.com/openid/v2/op?openid.ax.type.fullname=http://schema.openid.net/contact/fullname&openid.ax.required=email,fullname&openid.ns.atlassian=https://developer.atlassian.com/display/CROWDDEV/CrowdID%2BOpenID%2Bextensions%23CrowdIDOpenIDextensions-login-page-parameters&openid.ns.ax=http://openid.net/srv/ax/1.0&openid.return_to=https://sdog.jira.com/login/atlassianid?remember-me%3Dfalse&openid.ns=http://specs.openid.net/auth/2.0&openid.ax.type.email=http://schema.openid.net/contact/email&openid.ns.sreg=http://openid.net/extensions/sreg/1.1&openid.ax.mode=fetch_request&openid.atlassian.tenant=sdog.jira.com&openid.atlassian.application=ondemand&openid.ns.ext2=http://specs.openid.net/extensions/ui/1.0&openid.ext2.icon=true&openid.identity=http://specs.openid.net/auth/2.0/identifier_select&openid.realm=https://*.jira.com&openid.claimed_id=http://specs.openid.net/auth/2.0/identifier_select&openid.sreg.required=email,fullname&openid.mode=checkid_setup' -H 'Accept-Encoding: gzip,deflate,sdch' -H 'Accept-Language: en-US,en;q=0.8,nl;q=0.6' -H '__ATL_USER: admin' -H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.122 Safari/537.36' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8' -H 'Referer: https://id.atlassian.com/login?continue=https%3A%2F%2Fid.atlassian.com%2Fopenid%2Fv2%2Fop%3Fopenid.ax.type.fullname%3Dhttp%3A%2F%2Fschema.openid.net%2Fcontact%2Ffullname%26openid.ax.required%3Demail%2Cfullname%26openid.ns.atlassian%3Dhttps%3A%2F%2Fdeveloper.atlassian.com%2Fdisplay%2FCROWDDEV%2FCrowdID%252BOpenID%252Bextensions%2523CrowdIDOpenIDextensions-login-page-parameters%26openid.ns.ax%3Dhttp%3A%2F%2Fopenid.net%2Fsrv%2Fax%2F1.0%26openid.return_to%3Dhttps%3A%2F%2Fsdog.jira.com%2Flogin%2Fatlassianid%3Fremember-me%253Dfalse%26openid.ns%3Dhttp%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%26openid.ax.type.email%3Dhttp%3A%2F%2Fschema.openid.net%2Fcontact%2Femail%26openid.ns.sreg%3Dhttp%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1%26openid.ax.mode%3Dfetch_request%26openid.atlassian.tenant%3Dsdog.jira.com%26openid.atlassian.application%3Dondemand%26openid.ns.ext2%3Dhttp%3A%2F%2Fspecs.openid.net%2Fextensions%2Fui%2F1.0%26openid.ext2.icon%3Dtrue%26openid.identity%3Dhttp%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select%26openid.realm%3Dhttps%3A%2F%2F*.jira.com%26openid.claimed_id%3Dhttp%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0%2Fidentifier_select%26openid.sreg.required%3Demail%2Cfullname%26openid.mode%3Dcheckid_setup&application=ondemand&tenant=sdog.jira.com' -H 'Cookie: __ATL_TOKEN=<TOKEN_HERE>;mt.pevt=mr%3Dt1415380136%26mi%3D'2.2126138620.1401348482803'%26u%3D'https://www.atlassian.com/software/jira/try/'%26e%3D!(xi)%26ii%3D!('2,2,7904,,1416204185,2,1416204189')%26eoq%3D!t' -H 'Connection: keep-alive' -H 'Cache-Control: max-age=0' --compressed
      

      Spray output:

      2014-11-19 06:41:32,681 openid-spray-akka.actor.default-dispatcher-1804 WARN [spray.servlet.Servlet30ConnectorServlet] Illegal HTTP header 'cookie': Invalid input ',', expected CookieOctet, OptWS, ';' or EOI (line 1, pos 170):
      __ATL_TOKEN=;mt.pevt=mr%3Dt1415380136%26mi%3D2.2126138620.1401348482803%26u%3Dhttps://www.atlassian.com/software/jira/try/%26e%3D!(xi)%26ii%3D!(2,2,7904,,1416204185,2,1416204189)%26eoq%3D!t
      

      Attachments

        Issue Links

          Activity

            People

              dberrueta Diego Berrueta
              dberrueta Diego Berrueta
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: