Repository navigation
Fixed invalid path in CONNECT method requests. #34412
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 8 commits
edd8f6e
0825564
247401a
989cecd
e1283be
669ee65
c9f1597
d8039e3
9426cbb
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,6 +7,7 @@ const { | |
| const { setUnrefTimeout } = require('internal/timers'); | ||
| const { PerformanceEntry, notify } = internalBinding('performance'); | ||
|
|
||
| const VALID_PATH_REGEX = /^[_0-9A-Za-z]+(?:\.[_0-9A-Za-z]+)*\.?:(?:[1-9]|[1-9][0-9]{1,2}|[1-5][0-9]{3}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5])$/; | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Benchmarks tests may be required to assess whether performance has been affected.
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. @rickyes Could you guide me more about these benchmark tests, as how to write one?
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. @preyunk Usually there is no need to write additional
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The regex here does not properly account for the possibility of IPv6 addresses. For instance, new URL(`http://${path}`)If creating the URL is successful, check that the
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Also you need to check that |
||
| let nowCache; | ||
| let utcCache; | ||
|
|
||
|
|
@@ -32,6 +33,10 @@ function resetCache() { | |
| utcCache = undefined; | ||
| } | ||
|
|
||
| function isValidCONNECTPath(path) { | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It might be better to use the |
||
| return VALID_PATH_REGEX.test(path); | ||
| } | ||
|
|
||
| class HttpRequestTiming extends PerformanceEntry { | ||
| constructor(statistics) { | ||
| super(); | ||
|
|
@@ -53,5 +58,6 @@ module.exports = { | |
| kNeedDrain: Symbol('kNeedDrain'), | ||
| nowDate, | ||
| utcDate, | ||
| emitStatistics | ||
| emitStatistics, | ||
| isValidCONNECTPath | ||
| }; | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,42 @@ | ||
| // Flags: --expose-internals | ||
|
|
||
| 'use strict'; | ||
|
|
||
| const common = require('../common'); | ||
| const assert = require('assert'); | ||
| const http = require('http'); | ||
| const { isValidCONNECTPath } = require('internal/http'); | ||
|
|
||
| const server = http.createServer(); | ||
|
|
||
| server.on('connect', common.mustCall((req, stream) => { | ||
| assert.strictEqual(req.url, 'example.com:80'); | ||
| stream.end('HTTP/1.1 501 Not Implemented\r\n\r\n'); | ||
| })); | ||
|
|
||
| server.listen(0); | ||
|
|
||
| server.on('listening', common.mustCall(() => { | ||
| const url = new URL(`http://localhost:${server.address().port}/example.com:80`); | ||
| let req = http.request(url, { method: 'CONNECT' }).end(); | ||
| // invalid path | ||
| const invalidPathURL = new URL(`http://localhost:${server.address().port}/example.com`); | ||
| assert.throws( | ||
| () => { | ||
| req = http.request(invalidPathURL, { method: 'CONNECT' }).end(); | ||
| }, | ||
| { | ||
| code: 'ERR_INVALID_ARG_VALUE', | ||
| name: 'TypeError', | ||
| message: /^The argument 'options\.path' must be a valid host:port combo\. Received .+$/ | ||
| } | ||
| ); | ||
| req.once('connect', common.mustCall((res) => { | ||
| res.destroy(); | ||
| server.close(); | ||
| })); | ||
| })); | ||
|
|
||
| ['example.com', 'example.com:0', 'example.com:65536'].forEach((path) => { | ||
|
jasnell marked this conversation as resolved.
Outdated
|
||
| assert.strictEqual(isValidCONNECTPath(path), false); | ||
| }); | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
path[0] === '/'is much faster