Shrine 3.10.2
Security
-
The
derivation_endpointplugin now verifies the URL signature against the URL exactly as it was received. Previously, query parameters were decoded and re-encoded before verification, so the same signed URL could be requested through an unlimited number of variants that all passed verification. Since each variant is a separate cache key on a CDN, this could be used to bypass CDN caching and repeatedly trigger derivations on the server:/derivations/thumbnail/...?type=image%2Fwebp&signature=abc123 # original/derivations/thumbnail/...?%74ype=image%2Fwebp&signature=abc123 # encoded parameter name/derivations/thumbnail/...?&&type=image%2Fwebp&signature=abc123 # empty parameters/derivations/thumbnail/...?type=image%2Fwebp&signature=abc123?foo # appended queryThese variants now return a
403 Forbiddenresponse. Thesignaturequery parameter is also required to be the last parameter, which is where Shrine always puts it.
Backwards compatibility
- URLs generated by the
derivation_endpointplugin are unchanged, so existing URLs remain valid. However, if a proxy between the client and your application rewrites the query string (e.g. re-encodes characters, reorders parameters, or appends tracking parameters), signature verification will now fail for those requests.