Open Bug 646378 Opened 15 years ago Updated 3 years ago

GWT X-GWT-Permutation HTTP header not always included in POST to server

Categories

(Core :: Networking: HTTP, defect, P3)

x86
Linux
defect

Tracking

()

UNCONFIRMED

People

(Reporter: michael.anstis, Unassigned)

Details

(Whiteboard: [necko-backlog])

User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.10 (maverick) Firefox/3.6.15 Build Identifier: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.10 (maverick) Firefox/3.6.15 GWT2.1+ includes protection for XSRF attacks by including X-GWT-Permutation header in the HTTP POSTs. This header is checked by GWT to protect against XSRF attacks. When running a GWT2.1+ application in FireFox 3.6 GWT occasionally reports the header is missing, which leads to GWT security errors. The problem has only been experienced on FireFox 3.x in both Hosted Mode and Web Mode. Using other browsers (Chrome and IE) the problem cannot be replicated. I've ran Live Headers and the HTTP header is indeed missing:- Headers captured when GWT reports failure (NOTE: X-GWT-Permutation is missing) ------------------------------------------------------------------------------ Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 115 Connection: keep-alive Content-Length: 154 Content-Type: text/x-gwt-rpc; charset=utf-8 Referer: http://127.0.0.1:8888/org.drools.guvnor.Guvnor/Guvnor.html?gwt.codesv... Cookie: standalone_usage=true Pragma: no-cache Cache-Control: no-cache 7|0|4|http://127.0.0.1:8888/org.drools.guvnor.Guvnor/| 6808FDC8A4FA3491026441B59E4DB72A| org.drools.guvnor.client.rpc.RepositoryService|subscribe|1|2|3|4|0| HTTP/1.1 400 Bad Request <--- Caused by GWT failing to find header Content-Type: text/plain;charset=ISO-8859-1 Transfer-Encoding: chunked Date: Wed, 23 Mar 2011 20:11:04 GMT Server: Apache-Coyote/1.1 Connection: close Successful headers ------------------ http://127.0.0.1:8888/org.drools.guvnor.Guvnor/guvnorService POST /org.drools.guvnor.Guvnor/guvnorService HTTP/1.1 Host: 127.0.0.1:8888 User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.15) Gecko/ 20110303 Ubuntu/10.10 (maverick) Firefox/3.6.15 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/ *;q=0.8 Accept-Language: en-gb,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 115 Connection: keep-alive X-GWT-Permutation: HostedMode X-GWT-Module-Base: http://127.0.0.1:8888/org.drools.guvnor.Guvnor/ Content-Type: text/x-gwt-rpc; charset=utf-8 Referer: http://127.0.0.1:8888/org.drools.guvnor.Guvnor/Guvnor.html?gwt.codesv... Content-Length: 154 Cookie: standalone_usage=true Pragma: no-cache Cache-Control: no-cache 7|0|4|http://127.0.0.1:8888/org.drools.guvnor.Guvnor/| 41FA1D8B82DBBBC875605A4A29670D99| org.drools.guvnor.client.rpc.RepositoryService|subscribe|1|2|3|4|0| HTTP/1.1 200 OK Content-Disposition: attachment Content-Type: application/json;charset=utf-8 Content-Length: 48 Date: Wed, 23 Mar 2011 20:15:38 GMT Server: Apache-Coyote/1.1 This behaviour has also been reported by another: http://stackoverflow.com/questions/5429961/gwt-xsrf-sporadic-missing-x-gwt-permutation-header Reproducible: Sometimes Steps to Reproduce: Unfortunately the behaviour is sporadic and the only steps that can replicate the problem is to run a GWT2.1+ application and occasionally the error occurs. (GWT pre-2.1+ did not include the additional HTTP header). Actual Results: X-GWT-Permutation HTTP header is found to be missing. Expected Results: X-GWT-Permutation HTTP header should be present on all HTTP POSTs. Vanila FireFox3.6, plus "Firebug 1.6.2" and "Live HTTP Headers"
Another has reported here: https://support.mozilla.com/en-US/questions/802724?new=1 (info added here to make the connection)
* Approximately how frequently does this occur? * Are only X-GWT-Permutation headers apparently omitted, or are other headers also disappearing? * Does this problem occur on Firefox 4? * Does the problem occur if Firebug is not present?
1) It occurs very frequently: It occurs most notably when a new URL is requested for the first time, once the error has been thrown once for a given URL the same URL can be visited again without problem (e.g. refresh browser and navigate to the same screen). I am absolutely confident once a URL has been visited and the error thrown, the same URL can be revisited in the same session without problem. It would be fair to comment that I have not been able to test this exhaustively, but I get a general feeling this appears to be the behaviour. 2) (Unfortunately?) yes, I have only seen these headers missing - but then again these are the only headers I know to be checked for programmatically by another library and the only ones causing me issue. So there might be others missing, I simply don't know. Sorry. 3) Yes, downloaded vanila FF4.0 - Mozilla/5.0 (X11; Linux i686; rv:2.0) Gecko/20100101 Firefox/4.0 being ran as I type - and the problem remains. 4) Vanilla FF4.0 with all extensions disabled shows the same issue.
When I have encountered this bug, any header beginning with "X-" is stripped.
My use case has the client polling the server every 10 seconds. We get a broken request every 5 minutes (or perhaps just a touch longer). There are some cases where it an extra failure occurs between the "regularly scheduled" ones. I have at least one case where two requests from the same client arrived at the server at the same time, and both were missing the headers.
I only see this happen in 4.0 and at random times. Firefox seems to omit needed GWT header. I can't reproduce it in older versions of Firefox.
Version: unspecified → 3.6 Branch
Same problem here, I'm using a "X-CSRF-Token" header to prevent CSRFs. Actually, all my "X-Something" headers are stripped. I've observed the problem with Firefox 4.0.1 on Mac and Windows. The problem occurs randomly.
(In reply to comment #4) > When I have encountered this bug, any header beginning with "X-" is stripped. I'm seeing similar bug also w/FF 4.0.1 on Windows where FF is dropping "X-Requested-With: XMLHttpRequest" headers for AJAX requests.
Component: General → Networking: HTTP
Product: Firefox → Core
QA Contact: general → networking.http
Version: 3.6 Branch → unspecified
What are the values of the Origin header, Referer header, and Host header?
As requested ("Origin" was not captured, so I assume does not exist. Please note that successful POSTs, i.e. those with X- headers do not include an "Origin" header either):- Host: 127.0.0.1:8888 Referer: http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/Guvnor.html?gwt.codesvr=127.0.0.1:9997 Here's all headers, if you're interested:- http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/guvnorService POST /org.drools.guvnor.FastCompiledGuvnor/guvnorService HTTP/1.1 Host: 127.0.0.1:8888 User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.17) Gecko/20110422 Ubuntu/10.10 (maverick) Firefox/3.6.17 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-gb,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 115 Connection: keep-alive Content-Length: 394 Content-Type: text/x-gwt-rpc; charset=utf-8 Referer: http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/Guvnor.html?gwt.codesvr=127.0.0.1:9997 Pragma: no-cache Cache-Control: no-cache 7|0|10|http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/|2C67A7346773BB26A5BC1DFBAAF5EA1E|org.drools.guvnor.client.rpc.AssetService|findAssetPage|org.drools.guvnor.client.rpc.AssetPageRequest/4043140489|java.util.Arrays$ArrayList/1243019747|[Ljava.lang.String;/2600011424|enumeration|da98caef-e1c4-4f98-880c-46a740c9131f|java.lang.Integer/3438268394|1|2|3|4|1|5|5|6|7|1|8|0|9|10|10|0| HTTP/1.1 400 Bad Request Content-Type: text/plain;charset=ISO-8859-1 Transfer-Encoding: chunked Date: Fri, 03 Jun 2011 08:56:21 GMT Server: Apache-Coyote/1.1 Connection: close
Hi from Sync Operations. I confirmed several weeks ago at :rnewman's request that some Firefox 3.6.9-4.0 in the wild (but not yet in the lab) sporadically fail to include standard basic authorization headers when communicating with the Firefox Sync servers. This occurs in the midst of a series of automated HTTP requests that do include valid basic auth headers for a limited set of users. Each occurrence occurred within a batch of transactions no longer than a second or two, and was preceded immediately (0-1 seconds before) by valid authentication headers. This discovery led to a rewrite of certain portions of Firefox Sync to fail more gracefully (and retry automatically) when an unexpected 401 Unauthorized occurs due to this issue. As of when I was last involved, the core issue with Firefox itself has not yet been identified. After searching SUMO, :rnewman found this bugzilla entry, which appears to indicate by now that a wide variety of headers beyond just basic authentication are affected.
Still having the issue on both FF 6.0.2 / Windows XP 32 and FF 6.0.2 / OS X 10.7.2 I also have the issue with XSRF Checks on Symfony2 Framework, I'm not sure it's related. I could investigate.
Whiteboard: [necko-backlog]
Priority: -- → P1
Priority: P1 → P3
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.