Uh oh!
There was an error while loading. Please reload this page.
test: check that --insecure-http-parser works - #31253
Closed
sam-github wants to merge 1 commit into
Closed
Conversation
This was referenced Jan 7, 2020
nodejs-github-bot
commented
Jan 7, 2020
Collaborator
sam-githubforce-pushed
the
test-insecure-http-parser
branch
from
January 7, 2020 23:05
3207505 to
ecb644dComparenodejs-github-bot
commented
Jan 7, 2020
Collaborator
nodejs-github-bot
commented
Jan 8, 2020
Collaborator
richardlau
approved these changes
Jan 8, 2020
addaleax
reviewed
Jan 8, 2020
Uh oh!
There was an error while loading. Please reload this page.
sam-githubforce-pushed
the
test-insecure-http-parser
branch
from
January 8, 2020 18:18
38aaeb5 to
6514a0bComparesam-github
commented
Jan 8, 2020
ContributorAuthor
Note that the test fails when the required CLI param is not present: |
nodejs-github-bot
commented
Jan 8, 2020
Collaborator
Test that using --insecure-http-parser will disable validation of invalid characters in HTTP headers. See: - nodejs#30567
sam-githubforce-pushed
the
test-insecure-http-parser
branch
from
January 9, 2020 16:16
6514a0b to
57ef733Comparenodejs-github-bot
commented
Jan 9, 2020
Collaborator
sam-github
commented
Jan 9, 2020
ContributorAuthor
@addaleax @nodejs/http |
nodejs-github-bot
commented
Jan 9, 2020
Collaborator
BridgeAR
approved these changes
Jan 9, 2020
sam-github
commented
Jan 9, 2020
ContributorAuthor
Landed in e4bff13 |
sam-github added a commit
to sam-github/node
that referenced
this pull request
Jan 10, 2020
Test that using --insecure-http-parser will disable validation of invalid characters in HTTP headers. See: - nodejs#30567 PR-URL: nodejs#31253 Reviewed-By: Richard Lau <riclau@uk.ibm.com> Reviewed-By: Ruben Bridgewater <ruben@bridgewater.de>
sam-github added a commit
to sam-github/node
that referenced
this pull request
Jan 10, 2020
Test that using --insecure-http-parser will disable validation of invalid characters in HTTP headers. See: - nodejs#30567 PR-URL: nodejs#31253 Reviewed-By: Richard Lau <riclau@uk.ibm.com> Reviewed-By: Ruben Bridgewater <ruben@bridgewater.de>
Merged
zsw007 added a commit
to ibmruntimes/node
that referenced
this pull request
Feb 11, 2020
Backport ab1fcb8 Original commit message: Test that using --insecure-http-parser will disable validation of invalid characters in HTTP headers. See: - nodejs/node#30567 PR-URL: nodejs/node#31253 Backport-PR-URL: nodejs/node#30473 Reviewed-By: Richard Lau <riclau@uk.ibm.com> Reviewed-By: Ruben Bridgewater <ruben@bridgewater.de>
zsw007 added a commit
to ibmruntimes/node
that referenced
this pull request
Feb 12, 2020
Backport ab1fcb8 Original commit message: Test that using --insecure-http-parser will disable validation of invalid characters in HTTP headers. See: - nodejs/node#30567 PR-URL: nodejs/node#31253 Backport-PR-URL: nodejs/node#30473 Reviewed-By: Richard Lau <riclau@uk.ibm.com> Reviewed-By: Ruben Bridgewater <ruben@bridgewater.de>
zsw007 added a commit
to ibmruntimes/node
that referenced
this pull request
Feb 12, 2020
Backport ab1fcb8 Original commit message: Test that using --insecure-http-parser will disable validation of invalid characters in HTTP headers. See: - nodejs/node#30567 PR-URL: nodejs/node#31253 Backport-PR-URL: nodejs/node#30473 Reviewed-By: Richard Lau <riclau@uk.ibm.com> Reviewed-By: Ruben Bridgewater <ruben@bridgewater.de>
BaochengSu added a commit
to BaochengSu/node
that referenced
this pull request
Oct 21, 2020
Ported from OpenSUSE:nodejs8-8.17.0-lp152.147.1:CVE-2019-15605.patch Original commit message: commit e2c8f89 Author: Sam Roberts <vieuxtech@gmail.com> Date: Thu Jan 16 11:55:52 2020 -0800 test: using TE to smuggle reqs is not possible See: https://hackerone.com/reports/735748 PR-URL: https://github.com/nodejs-private/node-private/pull/192 Reviewed-By: Beth Griggs <Bethany.Griggs@uk.ibm.com> commit 49f4220 Author: Sam Roberts <vieuxtech@gmail.com> Date: Tue Feb 4 10:36:57 2020 -0800 deps: upgrade http-parser to v2.9.3 PR-URL: https://github.com/nodejs-private/http-parser-private/pull/4 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Sam Roberts <vieuxtech@gmail.com> commit d616722 Author: Sam Roberts <vieuxtech@gmail.com> Date: Tue Jan 7 14:24:54 2020 -0800 test: check that --insecure-http-parser works Test that using --insecure-http-parser will disable validation of invalid characters in HTTP headers. See: - nodejs#30567 Backport-PR-URL: nodejs#30471 PR-URL: nodejs#31253 Reviewed-By: Richard Lau <riclau@uk.ibm.com> Reviewed-By: Ruben Bridgewater <ruben@bridgewater.de> commit a9849c0 Author: Sam Roberts <vieuxtech@gmail.com> Date: Wed Nov 20 11:48:58 2019 -0800 http: opt-in insecure HTTP header parsing Allow insecure HTTP header parsing. Make clear it is insecure. See: - nodejs#30553 - nodejs#27711 (comment) - nodejs#30515 Backport-PR-URL: nodejs#30471 PR-URL: nodejs#30567 Reviewed-By: Fedor Indutny <fedor.indutny@gmail.com> Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Denys Otrishko <shishugi@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com> commit a28e5cc Author: Sam Roberts <vieuxtech@gmail.com> Date: Wed Nov 13 10:05:38 2019 -0800 deps: upgrade http-parser to v2.9.1 PR-URL: nodejs#30471 Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Jiawen Geng <technicalcute@gmail.com> Reviewed-By: Richard Lau <riclau@uk.ibm.com> Reviewed-By: Beth Griggs <Bethany.Griggs@uk.ibm.com> Signed-off-by: Su Baocheng <baocheng.su@siemens.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test that using --insecure-http-parser will disable validation of
invalid characters in HTTP headers.
See:
Checklist
make -j4 test(UNIX), orvcbuild test(Windows) passes