Bare tokens (without '=') were not prefixed, only key=value pairs were.
In practice this affected forward_fields, where a bare token such as
'nopassword' would land in extra_fields unprefixed instead of as
'forward_nopassword', allowing injection of internal auth control fields.
Gbp-Pq: Name 0002-auth-Fix-prefixing-forward_fields-without-a-value-fr.patch
for (; *args != NULL; args++) {
value = strchr(*args, '=');
if (value == NULL) {
- key = *args;
+ key = *prefix != '\0' ? t_strconcat(prefix, *args, NULL) : *args;
} else {
key = t_strdup_until(*args, value++);
if (*prefix != '\0')