Skip to content

OutgoingMessage should not allow writing more bytes than Content-Length #39041

Description

@ronag

I don't think we currently error if the user specifices a content-length header and then writes more bytes to the response. I think this is something we could detect and error. Some http clients have a hard time handling this case (especially with pipelining) and would be nice if we could help with reducing the probability of this occuring.

Activity

  1. added
    httpIssues and PRs related to the http subsystem.
    on Jun 15, 2021
  2. ronag commented on Jun 15, 2021

    @ronag
    MemberAuthor

    @nodejs/http wdyt?

  3. mcollina commented on Jun 15, 2021

    @mcollina
    SponsorMember

    I'm in favor if this is not costing much too much throughput.

    I think we should add a new option to enable the check (as a minor), and then make a breaking change to flip that default.

  4. added
    good first issueIssues that are suitable for first-time contributors.
    on Jun 15, 2021
  5. betochf commented on Jun 16, 2021

    @betochf

    @mcollina @ronag hey, I'm just getting started, do you mind if I try to pull this off?

  6. daukadolt commented on Jun 16, 2021

    @daukadolt

    Looks like an interesting ticket, good luck with it @betochf 👍

    Please do let me know though in case if I can take over 🙈

  7. jodevsa commented on Oct 30, 2021

    @jodevsa
    Contributor

    @betochf Are you still on it?

  8. manav014 commented on Dec 11, 2021

    @manav014

    May I start working on this issue? As I think I would be able to create a PR for the same.

  9. manav014 commented on Dec 13, 2021

    @manav014

    @ronag may please help me with a specific test case which I can add as a test and also I can use that to test my changes.

  10. mpodolsk commented on Jan 3, 2022

    @mpodolsk

    if this will be a perf drop, what about a config flag for strict validation?
    also this assumes that we know the size of the payload before sending it :) which from exp may not always be the case.
    I think its the RECEIVER of the content that should validate the size against the headers. :)

    there are very specific conditions when to send this header.
    https://datatracker.ietf.org/doc/html/rfc7230#section-3.3.2

    If we consider request payloads "inputs" its the receiving system that should validated those 🤔

  11. LoveSharmaDEV commented on Feb 26, 2022

    @LoveSharmaDEV

    Hi everyone !!!!!
    Good Day!!
    Its my first time contributing to an open source project.
    Wanna know if this issue is still being worked upon.
    And any insights for this issue would be very helpful.

  12. 74ankur09 commented on Apr 1, 2022

    @74ankur09

    Hey everyone,
    I am looking forward to contribute in this , so can anyone help me on how to start with contributing as I have just started the open source contribution .
    So please share the steps of how to start contributing here .

  13. sidwebworks commented on Aug 23, 2022

    @sidwebworks
    Contributor

    Hey @ronag is this issue still available for someone to take? I noticed some previously closed PRs due to some broken tests.

    Can I take this one and get this resolved?

  14. mcollina commented on Aug 23, 2022

    @mcollina
    SponsorMember

    Go for it!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    good first issueIssues that are suitable for first-time contributors.httpIssues and PRs related to the http subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions