Skip to main content

Shrine 3.10.2

Security​

  • The derivation_endpoint plugin now verifies the URL signature against the URL exactly as it was received. Previously, query parameters were decoded and re-encoded before verification, so the same signed URL could be requested through an unlimited number of variants that all passed verification. Since each variant is a separate cache key on a CDN, this could be used to bypass CDN caching and repeatedly trigger derivations on the server:

    /derivations/thumbnail/...?type=image%2Fwebp&signature=abc123 # original
    /derivations/thumbnail/...?%74ype=image%2Fwebp&signature=abc123 # encoded parameter name
    /derivations/thumbnail/...?&&type=image%2Fwebp&signature=abc123 # empty parameters
    /derivations/thumbnail/...?type=image%2Fwebp&signature=abc123?foo # appended query

    These variants now return a 403 Forbidden response. The signature query parameter is also required to be the last parameter, which is where Shrine always puts it.

Backwards compatibility​

  • URLs generated by the derivation_endpoint plugin are unchanged, so existing URLs remain valid. However, if a proxy between the client and your application rewrites the query string (e.g. re-encodes characters, reorders parameters, or appends tracking parameters), signature verification will now fail for those requests.