mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 10:40:47 +03:00
fix(esp_http_client): require https->https for cross-scheme redirects
esp_http_client_set_redirection() now rejects any redirect target whose scheme is not https:// when the origin is HTTPS. This catches http, ftp, ws and any other scheme before client state is mutated. Same-host / https-to-https redirects are unaffected. Apps that intentionally want mixed-scheme redirects can set disable_auto_redirect=true and handle HTTP_EVENT_REDIRECT.
This commit is contained in:
@@ -297,6 +297,7 @@ typedef enum {
|
||||
#define ESP_ERR_HTTP_RANGE_NOT_SATISFIABLE (ESP_ERR_HTTP_BASE + 10) /*!< HTTP 416 Range Not Satisfiable, requested range in header is incorrect */
|
||||
#define ESP_ERR_HTTP_READ_TIMEOUT (ESP_ERR_HTTP_BASE + 11) /*!< HTTP data read timeout */
|
||||
#define ESP_ERR_HTTP_INCOMPLETE_DATA (ESP_ERR_HTTP_BASE + 12) /*!< Incomplete data received, less than Content-Length or last chunk */
|
||||
#define ESP_ERR_HTTP_REDIRECT_DOWNGRADE (ESP_ERR_HTTP_BASE + 13) /*!< HTTPS origin redirected to a non-HTTPS scheme (downgrade blocked) */
|
||||
|
||||
/**
|
||||
* @brief Start a HTTP session
|
||||
|
||||
Reference in New Issue
Block a user