Skip to content

fix(backend): keep TLS fingerprinting when a request carries Next.js metadata - #15364

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/tls-fingerprint-next
Oct 6, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/tls-fingerprint-next

Conversation

@HouMinXi

@HouMinXi HouMinXi commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • isTlsRequestEligible requires every option key to be on an allow list. RequestInit.next is Next.js cache metadata and was not on the list, so any request carrying it silently fell back to a plain fetch and skipped TLS fingerprinting.
  • next is now allowed. It is not forwarded to the upstream transport. Any other unrecognized key still bypasses fingerprinting.

Related Issues

Validation

  • Change type: other (TLS fingerprint eligibility)
  • Focused tests: node --import tsx/esm --test tests/unit/tls-proxy-context.test.ts (30 pass)
  • eslint on the changed files, with the repo suppression file
  • Reconciled with release/v3.8.52 @ 23a1148486
  • Updated test covers the change
  • Defect injection: removing next: true turns the new assertion red with 0 !== 1, and the change was restored

Tests Added Or Updated

  • tests/unit/tls-proxy-context.test.ts (updated)

Coverage Notes

  • One case carries next and asserts the request still takes the TLS path and that next is not forwarded. A second case carries an unrecognized key and asserts it still bypasses TLS.

Reviewer Notes

  • The allow list gained exactly one key. The direct and the proxied paths share isTlsRequestEligible, so both are covered by the same change.

…metadata

isTlsRequestEligible requires every option key to be on an allow list.
RequestInit.next is Next.js cache metadata and was not on it, so any
request carrying it silently fell back to a plain fetch and skipped the
TLS fingerprint. next is not forwarded to the upstream transport. Other
unrecognized keys still bypass fingerprinting.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
@HouMinXi
HouMinXi requested a review from diegosouzapw as a code owner October 2, 2026 17:15
@diegosouzapw
diegosouzapw merged commit 2b2e546 into diegosouzapw:release/v3.8.52 Oct 6, 2026
43 of 51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(backend): RequestInit.next silently disables TLS fingerprint eligibility

2 participants