Skip to content

Commit bdf80a2

Browse files
authored
fix: Do not allow empty transfer-encoding. (#874)
Signed-off-by: Paolo Insogna <paolo@cowtech.it>
1 parent 01e105a commit bdf80a2

3 files changed

Lines changed: 55 additions & 3 deletions

File tree

‎src/llhttp/http.ts‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -685,16 +685,19 @@ export class HTTP {
685685

686686
const emptyContentLengthError = p.error(
687687
ERROR.INVALID_CONTENT_LENGTH, 'Empty Content-Length');
688-
const checkContentLengthEmptiness = this.load('header_state', {
688+
const emptyTransferEncodingError = p.error(
689+
ERROR.INVALID_TRANSFER_ENCODING, 'Empty Transfer-Encoding');
690+
const checkEmptyHeaderValue = this.load('header_state', {
689691
[HEADER_STATE.CONTENT_LENGTH]: emptyContentLengthError,
692+
[HEADER_STATE.TRANSFER_ENCODING]: emptyTransferEncodingError,
690693
}, this.setHeaderFlags(
691694
this.emptySpan(span.headerValue, onHeaderValueComplete)));
692695

693696
n('header_value_discard_lws')
694697
.match([ ' ', '\t' ], this.testLenientFlags(LENIENT_FLAGS.HEADERS, {
695698
1: n('header_value_discard_ws'),
696699
}, p.error(ERROR.INVALID_HEADER_TOKEN, 'Invalid header value char')))
697-
.otherwise(checkContentLengthEmptiness);
700+
.otherwise(checkEmptyHeaderValue);
698701

699702
// Multiple `Transfer-Encoding` headers should be treated as one, but with
700703
// values separate by a comma.

‎test/request/transfer-encoding.md‎

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,32 @@
11
Transfer-Encoding header
22
========================
33

4+
## Empty `Transfer-Encoding` with `Content-Length`
5+
6+
<!-- meta={"type": "request"} -->
7+
```http
8+
POST /first HTTP/1.1
9+
Transfer-Encoding:
10+
Content-Length: 5
11+
12+
hello
13+
```
14+
15+
```log
16+
off=0 message begin
17+
off=0 len=4 span[method]="POST"
18+
off=4 method complete
19+
off=5 len=6 span[url]="/first"
20+
off=12 url complete
21+
off=12 len=4 span[protocol]="HTTP"
22+
off=16 protocol complete
23+
off=17 len=3 span[version]="1.1"
24+
off=20 version complete
25+
off=22 len=17 span[header_field]="Transfer-Encoding"
26+
off=40 header_field complete
27+
off=42 error code=15 reason="Empty Transfer-Encoding"
28+
```
29+
430
## `chunked`
531

632
### Parsing and setting flag

‎test/response/transfer-encoding.md‎

Lines changed: 24 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,30 @@
11
Transfer-Encoding header
22
========================
33

4+
## Empty `Transfer-Encoding` with `Content-Length`
5+
6+
<!-- meta={"type": "response"} -->
7+
```http
8+
HTTP/1.1 200 OK
9+
Transfer-Encoding:
10+
Content-Length: 5
11+
12+
hello
13+
```
14+
15+
```log
16+
off=0 message begin
17+
off=0 len=4 span[protocol]="HTTP"
18+
off=4 protocol complete
19+
off=5 len=3 span[version]="1.1"
20+
off=8 version complete
21+
off=13 len=2 span[status]="OK"
22+
off=17 status complete
23+
off=17 len=17 span[header_field]="Transfer-Encoding"
24+
off=35 header_field complete
25+
off=37 error code=15 reason="Empty Transfer-Encoding"
26+
```
27+
428
## Trailing space on chunked body
529

630
<!-- meta={"type": "response"} -->
@@ -427,4 +451,3 @@ off=66 len=1 span[body]=lf
427451
off=67 len=1 span[body]=cr
428452
off=68 len=1 span[body]=lf
429453
```
430-

0 commit comments

Comments
 (0)