Repository navigation
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ContentCharset("UTF-8")currently rejects validContent-Type: text/plain; charset="UTF-8"requests with 415. Its substring extraction also readscharset=inside another quoted parameter rather than selecting the actual charset parameter. Parse the media parameters with the standard library, retaining case-insensitive charset matching and the existing fallback for absent or non-MIME header values.Normalize HTTP quoted pairs only within quoted strings before MIME parsing. This is needed because Go's MIME parser deliberately preserves some backslash escapes for legacy browser file paths, whereas HTTP quoted pairs represent the following byte. Escaped quotes and literal backslashes stay encoded for the MIME parser to decode once. Request headers and bodies remain untouched, and the existing bodyless-request bypass stays in place.
Validation on exact source
35fea3e25b3e1e02f154fc5bd4213070b309ad15:make testpasses on all eight combinations: router and middleware suites, 57 and 73 top-level tests respectively, with-race. Fullgo vet ./...also passes; scoped goimports v0.31.0 reports no changes. Every job verifies actual working-file SHA256 before and after all checks, normalized file blobs against this source, and unchanged HEAD/tracked diff/status.The standard parser has a measurable cost. On one Linux runner with Go 1.24.13, three samples of the direct parser benchmark measured unquoted headers at 99–100 ns/op (32 B, 1 allocation) before and 337 ns/op (344 B, 3 allocations) after. Quoted/quoted-pair/metadata headers measured 329/398/489 ns/op after, compared with approximately 99/102/82 ns/op before; the original implementation rejects the quoted regression inputs. These are parser microbenchmarks, not HTTP latency measurements. The raw samples, benchmark fixture, source/blob IDs, and SHA256 manifests are attached to the separate benchmark run.
The validation workflows and benchmark fixture are isolated to fork helper branches; this PR changes only the production parser and its regression tests.
AI assistance was used to prepare the implementation and tests. The native test results above were executed and checked against the recorded source and file hashes.