Skip to content

Validate HTTP::Request#method - #17255

Merged
straight-shoota merged 4 commits into
crystal-lang:masterfrom
straight-shoota:fix/http-request-validate-method
Aug 26, 2026
Merged

straight-shoota merged 4 commits into
crystal-lang:masterfrom
straight-shoota:fix/http-request-validate-method

Conversation

@straight-shoota

Copy link
Copy Markdown
Member

HTTP::Request.new and #method= should not allow arbitrary strings. This patch verifies that the given method is a valid HTTP token.
Invalid tokens would corrupt the HTTP message format.

@straight-shoota straight-shoota added kind:bug A bug in the code. Does not apply to documentation, specs, etc. topic:stdlib:networking labels Aug 19, 2026
@ysbaddaden ysbaddaden added this to the 1.22.0 milestone Aug 21, 2026
@ysbaddaden

Copy link
Copy Markdown
Collaborator

Sigh, CharLiteral#ord requires Crystal 1.11

Comment thread src/http/common.cr
{{table}}.to_slice
{% end %}
{% else %}
table = Slice(UInt8).new(256)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Polish: indentation is weird.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's the formatter acting weird. I don't think it's worth it to wrangle about it 🤷

I need to open an issue for that.

@ysbaddaden

Copy link
Copy Markdown
Collaborator

With RFC 0030 I wonder if we really need the fallback?

@straight-shoota

Copy link
Copy Markdown
Member Author

Right now we need it to merge this PR. We can drop it after adjusting the CI workflow.

@straight-shoota
straight-shoota merged commit cf50bc3 into crystal-lang:master Aug 26, 2026
52 checks passed
@straight-shoota
straight-shoota deleted the fix/http-request-validate-method branch August 26, 2026 17:08

This branch had an error being deployed

1 failed deployment
github-write — 4658ba8e Deployed Aug 26, 2026 by straight-shoota via Backport Pull Request #4375
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind:bug A bug in the code. Does not apply to documentation, specs, etc. topic:stdlib:networking

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants