Netdot icon indicating copy to clipboard operation
Netdot copied to clipboard

Invalid Cookie Format

Open MatVDS opened this issue 3 years ago • 2 comments

Not 100% sure if this is a configuration problem (netdot_apache2_ldap.conf?) or if its an issue in the code. Right now we are running Netdot ( v.1.0.7) not sure if this is the latest version as I don't manage the Netdot environment myself. But when trying to rebuild the Perl:Rest:Client module in Golang I encountered the problem that the cookie generated by netdot is not RFC6265 compliant. The issue seems to be that the cookie name set by the netdot server has : Apache2::SiteControl_Netdot in its name.
Considering ":" is not allowed in the name of a cookie following the RFC and is thus ignored by the Golang cookiejar. This also seems to be the case for the "/" in "path=/netdot/"

MatVDS avatar Feb 25 '22 15:02 MatVDS

Seems this was handled at one point in. https://github.com/cvicente/Netdot/pull/98 But it got reverted again?

MatVDS avatar Feb 25 '22 15:02 MatVDS

I just lost a few hours due to the auth cookie name being invalid 😭

pkmollman avatar Jun 08 '23 19:06 pkmollman