fix: require CR before LF terminating an HTTP/0.9 request line - #878
Open
MegaManSec wants to merge 1 commit into
Open
fix: require CR before LF terminating an HTTP/0.9 request line#878MegaManSec wants to merge 1 commit into
MegaManSec wants to merge 1 commit into
Conversation
The bare-LF exit from URL parsing shared `toHTTP09` with the CRLF exit, so a request line ending in a lone LF was always accepted. Route it through a separate `toHTTP09BareLF` node gated on `OPTIONAL_CR_BEFORE_LF`, matching how `res_status` already handles the response line.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A request line terminated by a lone LF is accepted unconditionally, because the bare-LF exit from URL parsing shares the
toHTTP09adaptor with the CRLF exit. The equivalent response-line case is already gated onOPTIONAL_CR_BEFORE_LFinres_status, so the two sides disagree:This adds a separate
toHTTP09BareLFexit node and routes it throughcheckIfAllowLFWithoutCR, so a bare LF after the URL errors withCR_EXPECTEDin strict mode and is still accepted whenLENIENT_FLAGS.OPTIONAL_CR_BEFORE_LFis set.Note this tightens strict-mode parsing:
GET /\n\nwas previously accepted and now errors. Callers relying on it need the lenient flag.Tests in
test/request/sample.mdcover both modes, mirroring the existing No carriage ret / No carriage ret (lenient) pair intest/response/sample.md.