Comment 0 for bug 1327414

Revision history for this message
John Dickinson (notmyname) wrote : www-authenticate value isn't quoted

The WWW-Authenticate header value (returned on a 401 response) includes user-supplied strings to indicate the proper auth realm. However, Swift un-quotes the URL and then sets the value in the response. This means that a URL can be constructed that includes new HTML content at the hoster's own domain.

For example:


The fix is to ensure the www-authenticate value is quoted