Skip to content

Upon on redirect(301) authentication header doesn't get removed #2680

@yliu342

Description

@yliu342

Environment

  • Android OS version: 15
  • Devices affected:
  • Maps SDK Version: 11.8.1

Observed behavior and steps to reproduce

The http stack used in Mapbox does not strip out Authentication header upon on receiving a redirect (301). This is a huge security risk as the authentication token is leaked to 3rd party.

Expected behavior

Authentication header should be removed upon on redirect

Notes / preliminary analysis

Additional links and references

Metadata

Metadata

Assignees

No one assigned

    Labels

    bug 🪲Something isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions