decode punycode public suffixes in PublicSuffixMatcher.verify - #876
Open
dxbjavid wants to merge 2 commits into
Open
decode punycode public suffixes in PublicSuffixMatcher.verify#876dxbjavid wants to merge 2 commits into
dxbjavid wants to merge 2 commits into
Conversation
Signed-off-by: Javid Khan <dxbjavid@gmail.com>
Contributor
Author
|
makes sense, done. normalisation now happens in verify and verifyInternal just assumes a normalised input. one thing worth flagging: DefaultHostnameVerifier.matchIdentity calls verifyInternal directly rather than through verify, so with the logic moved up it now relies on the identity already being in normalised form. that matches the pre-existing behaviour on master, but if you'd like that path covered too i'm happy to normalise the identity at that call site. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PublicSuffixMatcher.verify (through verifyInternal) resolves the domain against the suffix rules without the normalisation and punycode decoding that getDomainRoot and matches already apply, and the bundled list holds IDN suffixes in their Unicode form. So an ACE-encoded public suffix such as xn--h-2fa.no matches no rule and verify returns true, which lets the cookie PublicSuffixDomainFilter treat a whole IDN TLD as a registrable domain and accept a supercookie scoped to it, even though matches recognises the same suffix correctly. This decodes and lowercases the input in verifyInternal the same way getDomainRoot does, so both the ACE and Unicode forms are rejected consistently while genuine registrable subdomains under an IDN suffix are still allowed.