Merge branch 'fix/fix_esp_http_client_cross_origin_credentials' into 'master'

fix(esp_http_client): strip Authorization header on cross-origin redirect

Closes SEC-228 and SEC-049

See merge request espressif/esp-idf!48820
This commit is contained in:
Mahavir Jain
2026-07-06 12:20:51 +05:30
2 changed files with 82 additions and 0 deletions
@@ -1268,6 +1268,14 @@ esp_err_t esp_http_client_set_url(esp_http_client_handle_t client, const char *u
free(old_host);
return ESP_ERR_NO_MEM;
}
http_header_delete(client->request->headers, "Authorization");
free(client->connection_info.username);
client->connection_info.username = NULL;
free(client->connection_info.password);
client->connection_info.password = NULL;
free(client->auth_header);
client->auth_header = NULL;
_clear_auth_data(client);
/* Free cached data if any, as we are closing this connection */
esp_http_client_cached_buf_cleanup(client->response->buffer);
esp_http_client_close(client);