HTTP parser: restricting allowed characters in fields values.
According to RFC 7230 only printable 7-bit ASCII characters are allowed in field values.
This commit is contained in:
@@ -679,7 +679,8 @@ nxt_http_lookup_field_end(u_char *p, u_char *end)
|
||||
|
||||
#define nxt_field_end_test_char(ch) \
|
||||
\
|
||||
if (nxt_slow_path((ch) < 0x10)) { \
|
||||
/* Values below 0x20 become more than 0xdf. */ \
|
||||
if (nxt_slow_path((u_char) ((ch) - 0x20) > 0x5e)) { \
|
||||
return &(ch); \
|
||||
}
|
||||
|
||||
|
||||
@@ -280,6 +280,24 @@ static nxt_http_parse_test_case_t nxt_http_test_cases[] = {
|
||||
NXT_HTTP_PARSE_INVALID,
|
||||
NULL, { NULL }
|
||||
},
|
||||
{
|
||||
nxt_string("GET / HTTP/1.1\r\n"
|
||||
"Host: exa\bmple.com\r\n\r\n"),
|
||||
NXT_HTTP_PARSE_INVALID,
|
||||
NULL, { NULL }
|
||||
},
|
||||
{
|
||||
nxt_string("GET / HTTP/1.1\r\n"
|
||||
"Host: пример.испытание\r\n\r\n"),
|
||||
NXT_HTTP_PARSE_INVALID,
|
||||
NULL, { NULL }
|
||||
},
|
||||
{
|
||||
nxt_string("GET / HTTP/1.1\r\n"
|
||||
"Host: xn--e1afmkfd.xn--80akhbyknj4f\r\n\r\n"),
|
||||
NXT_DONE,
|
||||
NULL, { NULL }
|
||||
},
|
||||
{
|
||||
nxt_string("GET / HTTP/1.1\r\n"
|
||||
"X-Unknown-Header: value\r\n"
|
||||
|
||||
Reference in New Issue
Block a user