Repository navigation
OutgoingMessage should not allow writing more bytes than Content-Length #39041
Description
Activity
- addedhttpIssues and PRs related to the http subsystem.Issues and PRs related to the http subsystem.
on Jun 15, 2021 @nodejs/http wdyt?
I'm in favor if this is not costing much too much throughput.
I think we should add a new option to enable the check (as a minor), and then make a breaking change to flip that default.
- addedgood first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.
on Jun 15, 2021 Looks like an interesting ticket, good luck with it @betochf 👍
Please do let me know though in case if I can take over 🙈
@betochf Are you still on it?
May I start working on this issue? As I think I would be able to create a PR for the same.
Reacted by Robert Nagy@ronag may please help me with a specific test case which I can add as a test and also I can use that to test my changes.
if this will be a perf drop, what about a config flag for strict validation?
also this assumes that we know the size of the payload before sending it :) which from exp may not always be the case.
I think its the RECEIVER of the content that should validate the size against the headers. :)there are very specific conditions when to send this header.
https://datatracker.ietf.org/doc/html/rfc7230#section-3.3.2If we consider request payloads "inputs" its the receiving system that should validated those 🤔
Hi everyone !!!!!
Good Day!!
Its my first time contributing to an open source project.
Wanna know if this issue is still being worked upon.
And any insights for this issue would be very helpful.Hey everyone,
I am looking forward to contribute in this , so can anyone help me on how to start with contributing as I have just started the open source contribution .
So please share the steps of how to start contributing here .Hey @ronag is this issue still available for someone to take? I noticed some previously closed PRs due to some broken tests.
Can I take this one and get this resolved?
Go for it!
Reacted by SidReacted by Sid
I don't think we currently error if the user specifices a content-length header and then writes more bytes to the response. I think this is something we could detect and error. Some http clients have a hard time handling this case (especially with pipelining) and would be nice if we could help with reducing the probability of this occuring.