Repository navigation
Overzealous link header validation in writeEarlyHints #46453
Copy link
Copy link
Closed
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.good first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.httpIssues and PRs related to the http subsystem.Issues and PRs related to the http subsystem.
Description
Activity
- addedhttpIssues and PRs related to the http subsystem.Issues and PRs related to the http subsystem.
on Feb 1, 2023 https://github.com/orgs/nodejs/teams/http what was the thinking there?
This is just a bug and no one caught it.
As for the script validation, the contributor proposed it and it seemed ok to me.Can you take a look @anonrig @Uzlopak? You both discussed this problem in: https://github.com/nodejs/node/pull/44820/files#r983969846.
- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.good first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.
on Feb 1, 2023 I really doesn't know why
Linkheader is the only exception to own a validation.
Maybe it provide a better DX, but in-consistence on behavior really cause a lot of confusion to the user.- added a commit that references this issue
on Feb 23, 2023 - added a commit that references this issue
on Mar 13, 2023 - added a commit that references this issue
on Apr 11, 2023 Can this also be fixed on Node 18?
@nithin-murali-arch Isn't this fixed in 18.16.0? #46466 has been backported there.
Metadata
Metadata
Assignees
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.good first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.httpIssues and PRs related to the http subsystem.Issues and PRs related to the http subsystem.
Version
v19.5.0
Platform
Darwin Kernel Version 22.2.0: Fri Nov 11 02:03:51 PST 2022; root:xnu-8792.61.2~4/RELEASE_ARM64_T6000 arm64
Subsystem
http
What steps will reproduce the bug?
How often does it reproduce? Is there a required condition?
No response
What is the expected behavior?
No response
What do you see instead?
Additional information
This appears to be an overzelous validation that requires all link parameters to be followed by an
=.Per the ABNF in RFC8288 https://www.rfc-editor.org/rfc/rfc8288.html#section-3 the
=is optional along with the parameter value.Additionally it seems that the validation restricts parameters to a preset list of those headers currently defined by the HTML spec. This seems in conflict with RFC8288 which doesn't appear to place any restrictions on parameters, which seems more relevant that the parameters that happen to be specified in the current HTML specification.