Improve header handling on cross-origin redirects in Bazel downloader. When following redirects in HttpConnectorMultiplexer, update host comparison in getHeaderFunction to be case-insensitive per RFC 3986 ยง3.2.2. Also add Cookie2 (RFC 2965) to the set of sensitive headers stripped during cross-origin HTTP redirects alongside Authorization, Proxy-Authorization, and Cookie. PiperOrigin-RevId: 955279459 Change-Id: I0bff222b34e10130bb55b11dc9b8c0ab33499700
{Fast, Correct} - Choose two
Build and test software of any size, quickly and reliably.
Speed up your builds and tests: Bazel rebuilds only what is necessary. With advanced local and distributed caching, optimized dependency analysis and parallel execution, you get fast and incremental builds.
One tool, multiple languages: Build and test Java, C++, Android, iOS, Go, and a wide variety of other language platforms. Bazel runs on Windows, macOS, and Linux.
Scalable: Bazel helps you scale your organization, codebase, and continuous integration solution. It handles codebases of any size, in multiple repositories or a huge monorepo.
Extensible to your needs: Easily add support for new languages and platforms with Bazel's familiar extension language. Share and re-use language rules written by the growing Bazel community.
To report a security issue, please email security@bazel.build with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed as a vulnerability, we will open a Security Advisory. This project follows a 90 day disclosure timeline.
See CONTRIBUTING.md