Project

Profile

Help

Issue #8816

closed

Syncing a repo with sles_auth_token set on the remote, may try to download kickstart files incorrectly

Added by jsherril@redhat.com over 3 years ago. Updated over 3 years ago.

Status:
CLOSED - CURRENTRELEASE
Priority:
Normal
Assignee:
Sprint/Milestone:
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Version:
Platform Release:
OS:
Triaged:
Yes
Groomed:
No
Sprint Candidate:
No
Tags:
Katello
Sprint:
Quarter:

Description

If you try to sync: http://distro.ibiblio.org/centos/7.9.2009/os/x86_64/

with the sles_auth_token set to: foo=bar (or any param/value). The Sync will fail with:

403, message='Forbidden', url=URL('http://distro.ibiblio.org/centos/7.9.2009/os/x86_64/LiveOS/squashfs.img/?foo=bar')

Notice that an extra slash is added to the url, it likely should be: http://distro.ibiblio.org/centos/7.9.2009/os/x86_64/LiveOS/squashfs.img?foo=bar

Note that this repo is not actually a SLES repo, and this was discovered accidentally due to katello's aggressive nature of using the sles_auth_token for all get params on a repo, but this will also be tackled (https://projects.theforeman.org/issues/32660)

Actions #1

Updated by jsherril@redhat.com over 3 years ago

  • Description updated (diff)
Actions #2

Updated by dalley over 3 years ago

@Justin, is this an issue that impacts all SLES repos, or an issue that occurs because this option was used on a non-SLES repo?

Actions #3

Updated by jsherril@redhat.com over 3 years ago

its mostly because it was used on a non-sles repo, but i suspect it could happen on a sles repo if it includes kickstart files. It may return a 404 instead of a 403 depending on the webserver in use

Actions #4

Updated by dalley over 3 years ago

  • Triaged changed from No to Yes
Actions #5

Updated by dalley over 3 years ago

  • Status changed from NEW to ASSIGNED
  • Assignee set to dalley
Actions #6

Updated by dalley over 3 years ago

This turned out to be a really simple issue so I just went ahead and fixed it.

Actions #7

Updated by pulpbot over 3 years ago

  • Status changed from ASSIGNED to POST

Added by dalley over 3 years ago

Revision 82e9ac49 | View on GitHub

Don't add a trailing slash any time that sles_auth_token is present

closes: #8816 https://pulp.plan.io/issues/8816

Actions #8

Updated by dalley over 3 years ago

  • Status changed from POST to MODIFIED
Actions #9

Updated by pulpbot over 3 years ago

  • Sprint/Milestone set to 3.13.0
Actions #10

Updated by pulpbot over 3 years ago

  • Status changed from MODIFIED to CLOSED - CURRENTRELEASE

Also available in: Atom PDF