Skip to content

[Agricola] AGR-2026-103: Challenge auth-param names are parsed case-sensitively #231

Description

@mpp-agricola

AGR-2026-103 — Challenge auth-param names are parsed case-sensitively

Last observed by the head-to-head audit at 2026-09-14T09:17:13.387847Z.

Audited heads

Target Repository Commit Conformance Semantic review
typescript wevm/mppx 3c14a65a7ea5 Complete Reference
python tempoxyz/pympp 7988d1cda5c4 Complete Complete
rust tempoxyz/mpp-rs d859a13d74ef Complete Complete
go tempoxyz/mpp-go 9fcf9a47c61b Complete Complete
java stripe/mpp-java ca57f0998545 Complete Complete
ruby stripe/mpp-rb 3b9e2923c67b Complete Complete

Finding

  • Fingerprint: semantic:challenge-parsing/case-insensitive-auth-parameter-names
  • Source: semantic
  • Affected SDKs: python, rust
  • Clean SDKs: none
  • Not reported by semantic review: go, java, ruby
  • Canonical reference: draft-ietf-httpauth-payment §5.1; RFC 9110 §11.2
  • Severity: medium
  • Confidence: high

Evidence

SDK Canonical evidence SDK evidence Suggested test
python parseAuthParams — Lowercases each parsed auth-parameter name before storage and duplicate detection. _parse_auth_params — Stores parameter names with their original casing; required-field lookup later uses lowercase keys. Parse a valid challenge with ID, Realm, Method, Intent, and Request parameter names and assert success; then add both realm and Realm and assert a duplicate-parameter error.
rust parseAuthParams — Lowercases each auth-param name before storage and duplicate detection. parse_auth_params — Stores auth-param names with their original casing; parse_www_authenticate later retrieves only lowercase names. Parse a valid challenge whose required parameter names are ID, Realm, Method, Intent, and Request; assert it equals the lowercase form, then assert id=... plus ID=... is rejected as a duplicate.

python: The canonical challenge parser normalizes auth-parameter names to lowercase and detects duplicates after normalization. The target retains original casing but subsequently looks up required parameters using lowercase names. A valid challenge using Realm, Method, or other differently cased parameter names is therefore rejected, while mixed-case duplicates can evade duplicate detection.

rust: HTTP authentication parameter names are case-insensitive. Canonical mppx normalizes every parsed name to lowercase, so fields such as ID, Realm, or Request work and differently cased duplicates are rejected. The Rust parser retains the original spelling and subsequently looks up lowercase keys. Consequently, an otherwise valid challenge using uppercase or mixed-case required parameter names is rejected as missing fields; differently cased duplicates can also evade duplicate detection.

Available /ag commands

Post a command as a new comment. Only configured maintainers can run these commands.

Target Automation Status Pull request
rust pr Queued —
python pr Queued —

Quick action

Use GitHub's copy button, then post this command as a comment:

/ag fix
Command What it does
/ag fix Opens or retries draft fixes for every affected PR-enabled SDK.
/ag fix python Opens or retries the draft fix for python only.
/ag fix rust Opens or retries the draft fix for rust only.
/ag fix "instruction" Applies the instruction to affected fixes; recorded PRs also incorporate unresolved review feedback and failed CI.
/ag status Reports the current state of linked remediation pull requests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agricolaIssues managed by AgricolapythonIssues affecting the python SDKrustPull requests that update rust code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions