Security implications of userinfo in URL for java.net.HttpURLConnection

Viewed 476

A string representing a URL is passed to me containing the username and password in the userinfo part of the URL. If I use this URL to open a java.net.HttpURLConnection it does not automatically create the Authorization header, so I am creating the header value and setting it on the connection myself:

String host = "https://user:password@example.com";
java.net.URL url = new java.net.URL(host);

String userInfo = url.getUserInfo(); // contains user:password
String authHeader = createAuthHeader(userInfo);

HttpURLConnection connection = (HttpURLConnection) url.openConnection();
connection.setRequestProperty("Authorization", authHeader);

// connection used to open OutputStream, write data, and closed

HTTPS is used to protect the Authorization header.

I'm unable to change this string and so unable to separate the userinfo from the remaining URL string.

My question is, are there still security implications for having the userInfo part of java.net.URL set to "user:password", specifically with respect to the server receiving this request or anyone intercepting the request? Or would java.net.HttpURLConnection not send that information at all.

0 Answers
Related