Uploaded image for project: 'apiman (API Management)'
  1. apiman (API Management)
  2. APIMAN-584

Policy: URL Re-writing

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 1.1.6.Final, 1.1.x
    • None
    • None
    • None

    Description

      I was testing the gateway with google.co.uk. In its response, it set the Location header to 'http://www.google.com', and returned a 302 redirect, which caused my browser to immediately bounce to that location.

      This essentially bypasses the gateway. Perhaps this is something we should treat as normal behaviour in the situation such as above - but potentially there's a catch :

      A site can redirect to a different path on the same site, using a full URL (spec allows full and relative).

      e.g. let's imagine 'example.com' redirects to 'example.com/content/' with a full URL. That would immediately confuse the browser, and if it was a service only available behind the gateway, it will break for the user.

      This may or may not be worth addressing, WDYT.

      Attachments

        Activity

          People

            ewittman@redhat.com Eric Wittmann
            msavy_jira Marc Savy (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: