You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A header name has to match the field-name syntax (which is token) and does not allow all kind of values such as 0x00.
The specifications do not seem to specify however how to deal with invalid header names.
Should the whole response be discarded (network error)? Should only the invalid header (line) be discarded? Should the Null byte simply be ignored or treated as a space?
One tricky aspect here is that at least Chromium and perhaps other browsers as well have different parsing between HTTP and HTTPS so tests need to take that into consideration. And writing (tentative) tests is probably what we need to start with before we can require things in Fetch one way or another. If you're interested in writing tests for the cases mentioned in that issue that'd be most helpful.
What is the issue with the Fetch Standard?
A
header name
has to match thefield-name
syntax (which is token) and does not allow all kind of values such as 0x00.The specifications do not seem to specify however how to deal with invalid header names.
Should the whole response be discarded (network error)? Should only the invalid header (line) be discarded? Should the Null byte simply be ignored or treated as a space?
Example URL with 0x00: Example
ERR_INVALID_HTTP_RESPONSE
Related:
The text was updated successfully, but these errors were encountered: