fix(token): only follow pagination links on the registry origin - #10071
Open
ManoharPaturi wants to merge 1 commit into
Open
ManoharPaturi wants to merge 1 commit into
ManoharPaturi wants to merge 1 commit into
Conversation
The token list pagination url comes straight from the registry response and was fetched as-is. npm-registry-fetch attaches the registry credentials to any request whose host matches the registry host, so a response that swaps the scheme (an https registry answering with an http link) would send the bearer token in cleartext, and a link pointing at another origin would turn the client into a request generator for a host the user never configured. Only follow pagination links that stay on the configured registry origin, warn and stop when a link leaves it, and tolerate a response that omits the urls object entirely, which used to crash the command.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
npm token listandnpm token revokepage through/-/npm/v1/tokensby following theurls.nextlink taken verbatim from the registry response:Two consequences:
http://link) is still sent theAuthorizationheader, now in cleartext. A compromised or hostile registry can use this to expose the bearer token to an on-path attacker.Reproducing the first case before this change, with the mock registry replying
urls.next = 'http://registry.npmjs.org/-/npm/v1/tokens?next=...', the command issues the plaintext request (blocked in tests only by nock'sdisableNetConnect):Separately, a response that omits the
urlsobject entirely crashes the command with a TypeError.Solution
Resolve the next link against the configured registry and only follow it when its origin (scheme, host, port) matches the registry origin. Otherwise stop paginating and warn, so a truncated listing is visible rather than silent. Non-string or missing links, including a missing
urlsobject, now end pagination cleanly.Test Evidence
Four tests added to
test/lib/commands/token.js:urlsobject lists tokens instead of crashing.The downgrade test fails on the previous code with the disallowed plaintext request shown above. Full file is green with this change:
npx tap test/lib/commands/token.js.References
node_modules/npm-registry-fetch/lib/auth.js