Tweaked check_signature() for GET variables.
Instead of unconditionally stripping ? variables when retrieving the keyId, try first calling actor_request() directly, and only strip them and retry if it fails.
This commit is contained in:
@@ -182,14 +182,22 @@ int check_signature(const xs_dict *req, xs_str **err)
|
||||
if ((p = strchr(keyId, '#')) != NULL)
|
||||
*p = '\0';
|
||||
|
||||
/* also strip cgi variables */
|
||||
if ((p = strchr(keyId, '?')) != NULL)
|
||||
*p = '\0';
|
||||
|
||||
xs *actor = NULL;
|
||||
int status;
|
||||
|
||||
if (!valid_status((status = actor_request(NULL, keyId, &actor)))) {
|
||||
/* does it have ? variables? */
|
||||
if ((p = strchr(keyId, '?')) != NULL) {
|
||||
/* try first with them */
|
||||
if (!valid_status((status = actor_request(NULL, keyId, &actor)))) {
|
||||
*p = '\0';
|
||||
/* retry stripping them */
|
||||
status = actor_request(NULL, keyId, &actor);
|
||||
}
|
||||
}
|
||||
else
|
||||
status = actor_request(NULL, keyId, &actor);
|
||||
|
||||
if (!valid_status(status)) {
|
||||
*err = xs_fmt("actor request error %s %d", keyId, status);
|
||||
return 0;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user