Open
Bug 646378
Opened 15 years ago
Updated 3 years ago
GWT X-GWT-Permutation HTTP header not always included in POST to server
Categories
(Core :: Networking: HTTP, defect, P3)
Tracking
()
UNCONFIRMED
People
(Reporter: michael.anstis, Unassigned)
Details
(Whiteboard: [necko-backlog])
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.10 (maverick) Firefox/3.6.15
Build Identifier: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.10 (maverick) Firefox/3.6.15
GWT2.1+ includes protection for XSRF attacks by including X-GWT-Permutation header in the HTTP POSTs. This header is checked by GWT to protect against XSRF attacks.
When running a GWT2.1+ application in FireFox 3.6 GWT occasionally reports the header is missing, which leads to GWT security errors.
The problem has only been experienced on FireFox 3.x in both Hosted Mode and Web Mode. Using other browsers (Chrome and IE) the problem cannot be replicated.
I've ran Live Headers and the HTTP header is indeed missing:-
Headers captured when GWT reports failure (NOTE: X-GWT-Permutation is missing)
------------------------------------------------------------------------------
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Content-Length: 154
Content-Type: text/x-gwt-rpc; charset=utf-8
Referer: http://127.0.0.1:8888/org.drools.guvnor.Guvnor/Guvnor.html?gwt.codesv...
Cookie: standalone_usage=true
Pragma: no-cache
Cache-Control: no-cache
7|0|4|http://127.0.0.1:8888/org.drools.guvnor.Guvnor/|
6808FDC8A4FA3491026441B59E4DB72A|
org.drools.guvnor.client.rpc.RepositoryService|subscribe|1|2|3|4|0|
HTTP/1.1 400 Bad Request <--- Caused by GWT failing to find header
Content-Type: text/plain;charset=ISO-8859-1
Transfer-Encoding: chunked
Date: Wed, 23 Mar 2011 20:11:04 GMT
Server: Apache-Coyote/1.1
Connection: close
Successful headers
------------------
http://127.0.0.1:8888/org.drools.guvnor.Guvnor/guvnorService
POST /org.drools.guvnor.Guvnor/guvnorService HTTP/1.1
Host: 127.0.0.1:8888
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.15) Gecko/
20110303 Ubuntu/10.10 (maverick) Firefox/3.6.15
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/
*;q=0.8
Accept-Language: en-gb,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
X-GWT-Permutation: HostedMode
X-GWT-Module-Base: http://127.0.0.1:8888/org.drools.guvnor.Guvnor/
Content-Type: text/x-gwt-rpc; charset=utf-8
Referer: http://127.0.0.1:8888/org.drools.guvnor.Guvnor/Guvnor.html?gwt.codesv...
Content-Length: 154
Cookie: standalone_usage=true
Pragma: no-cache
Cache-Control: no-cache
7|0|4|http://127.0.0.1:8888/org.drools.guvnor.Guvnor/|
41FA1D8B82DBBBC875605A4A29670D99|
org.drools.guvnor.client.rpc.RepositoryService|subscribe|1|2|3|4|0|
HTTP/1.1 200 OK
Content-Disposition: attachment
Content-Type: application/json;charset=utf-8
Content-Length: 48
Date: Wed, 23 Mar 2011 20:15:38 GMT
Server: Apache-Coyote/1.1
This behaviour has also been reported by another: http://stackoverflow.com/questions/5429961/gwt-xsrf-sporadic-missing-x-gwt-permutation-header
Reproducible: Sometimes
Steps to Reproduce:
Unfortunately the behaviour is sporadic and the only steps that can replicate the problem is to run a GWT2.1+ application and occasionally the error occurs. (GWT pre-2.1+ did not include the additional HTTP header).
Actual Results:
X-GWT-Permutation HTTP header is found to be missing.
Expected Results:
X-GWT-Permutation HTTP header should be present on all HTTP POSTs.
Vanila FireFox3.6, plus "Firebug 1.6.2" and "Live HTTP Headers"
| Reporter | ||
Comment 1•15 years ago
|
||
Another has reported here: https://support.mozilla.com/en-US/questions/802724?new=1 (info added here to make the connection)
Comment 2•15 years ago
|
||
* Approximately how frequently does this occur?
* Are only X-GWT-Permutation headers apparently omitted, or are other headers also disappearing?
* Does this problem occur on Firefox 4?
* Does the problem occur if Firebug is not present?
| Reporter | ||
Comment 3•15 years ago
|
||
1) It occurs very frequently: It occurs most notably when a new URL is requested for the first time, once the error has been thrown once for a given URL the same URL can be visited again without problem (e.g. refresh browser and navigate to the same screen). I am absolutely confident once a URL has been visited and the error thrown, the same URL can be revisited in the same session without problem. It would be fair to comment that I have not been able to test this exhaustively, but I get a general feeling this appears to be the behaviour.
2) (Unfortunately?) yes, I have only seen these headers missing - but then again these are the only headers I know to be checked for programmatically by another library and the only ones causing me issue. So there might be others missing, I simply don't know. Sorry.
3) Yes, downloaded vanila FF4.0 - Mozilla/5.0 (X11; Linux i686; rv:2.0) Gecko/20100101 Firefox/4.0 being ran as I type - and the problem remains.
4) Vanilla FF4.0 with all extensions disabled shows the same issue.
Comment 4•15 years ago
|
||
When I have encountered this bug, any header beginning with "X-" is stripped.
My use case has the client polling the server every 10 seconds. We get a broken request every 5 minutes (or perhaps just a touch longer). There are some cases where it an extra failure occurs between the "regularly scheduled" ones.
I have at least one case where two requests from the same client arrived at the server at the same time, and both were missing the headers.
I only see this happen in 4.0 and at random times. Firefox seems to omit needed GWT header. I can't reproduce it in older versions of Firefox.
Updated•15 years ago
|
Version: unspecified → 3.6 Branch
Comment 7•15 years ago
|
||
Same problem here, I'm using a "X-CSRF-Token" header to prevent CSRFs. Actually, all my "X-Something" headers are stripped.
I've observed the problem with Firefox 4.0.1 on Mac and Windows. The problem occurs randomly.
Comment 8•15 years ago
|
||
(In reply to comment #4)
> When I have encountered this bug, any header beginning with "X-" is stripped.
I'm seeing similar bug also w/FF 4.0.1 on Windows where FF is dropping "X-Requested-With: XMLHttpRequest" headers for AJAX requests.
Updated•15 years ago
|
Component: General → Networking: HTTP
Product: Firefox → Core
QA Contact: general → networking.http
Version: 3.6 Branch → unspecified
Comment 9•15 years ago
|
||
What are the values of the Origin header, Referer header, and Host header?
| Reporter | ||
Comment 10•15 years ago
|
||
As requested ("Origin" was not captured, so I assume does not exist. Please note that successful POSTs, i.e. those with X- headers do not include an "Origin" header either):-
Host: 127.0.0.1:8888
Referer: http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/Guvnor.html?gwt.codesvr=127.0.0.1:9997
Here's all headers, if you're interested:-
http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/guvnorService
POST /org.drools.guvnor.FastCompiledGuvnor/guvnorService HTTP/1.1
Host: 127.0.0.1:8888
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.9.2.17) Gecko/20110422 Ubuntu/10.10 (maverick) Firefox/3.6.17
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-gb,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Content-Length: 394
Content-Type: text/x-gwt-rpc; charset=utf-8
Referer: http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/Guvnor.html?gwt.codesvr=127.0.0.1:9997
Pragma: no-cache
Cache-Control: no-cache
7|0|10|http://127.0.0.1:8888/org.drools.guvnor.FastCompiledGuvnor/|2C67A7346773BB26A5BC1DFBAAF5EA1E|org.drools.guvnor.client.rpc.AssetService|findAssetPage|org.drools.guvnor.client.rpc.AssetPageRequest/4043140489|java.util.Arrays$ArrayList/1243019747|[Ljava.lang.String;/2600011424|enumeration|da98caef-e1c4-4f98-880c-46a740c9131f|java.lang.Integer/3438268394|1|2|3|4|1|5|5|6|7|1|8|0|9|10|10|0|
HTTP/1.1 400 Bad Request
Content-Type: text/plain;charset=ISO-8859-1
Transfer-Encoding: chunked
Date: Fri, 03 Jun 2011 08:56:21 GMT
Server: Apache-Coyote/1.1
Connection: close
Comment 11•15 years ago
|
||
Hi from Sync Operations.
I confirmed several weeks ago at :rnewman's request that some Firefox 3.6.9-4.0 in the wild (but not yet in the lab) sporadically fail to include standard basic authorization headers when communicating with the Firefox Sync servers. This occurs in the midst of a series of automated HTTP requests that do include valid basic auth headers for a limited set of users. Each occurrence occurred within a batch of transactions no longer than a second or two, and was preceded immediately (0-1 seconds before) by valid authentication headers.
This discovery led to a rewrite of certain portions of Firefox Sync to fail more gracefully (and retry automatically) when an unexpected 401 Unauthorized occurs due to this issue. As of when I was last involved, the core issue with Firefox itself has not yet been identified. After searching SUMO, :rnewman found this bugzilla entry, which appears to indicate by now that a wide variety of headers beyond just basic authentication are affected.
Comment 12•14 years ago
|
||
Still having the issue on both FF 6.0.2 / Windows XP 32 and FF 6.0.2 / OS X 10.7.2
I also have the issue with XSRF Checks on Symfony2 Framework, I'm not sure it's related. I could investigate.
Updated•10 years ago
|
Whiteboard: [necko-backlog]
Comment 13•9 years ago
|
||
Bulk change to priority: https://bugzilla.mozilla.org/show_bug.cgi?id=1399258
Priority: -- → P1
Comment 14•9 years ago
|
||
Bulk change to priority: https://bugzilla.mozilla.org/show_bug.cgi?id=1399258
Priority: P1 → P3
Updated•3 years ago
|
Severity: normal → S3
You need to log in
before you can comment on or make changes to this bug.
Description
•