mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-08 16:04:46 +07:00
Reject trailing characters in HTTP quality values (#2590)
parse_quality accepted values such as q=0.5junk because it checked only the conversion error and ignored the returned end pointer. Require the numeric parser to consume the complete q parameter so malformed Accept values are rejected and invalid Accept-Encoding weights are ignored. Add regression cases for both headers.
This commit is contained in:
@@ -1059,6 +1059,10 @@ TEST(ParseAcceptHeaderTest, InvalidCases) {
|
||||
EXPECT_FALSE(detail::parse_accept_header(
|
||||
"text/html;q=invalid,application/json", result));
|
||||
|
||||
// A valid numeric prefix does not make the entire quality value valid.
|
||||
EXPECT_FALSE(detail::parse_accept_header(
|
||||
"text/html;q=0.5junk,application/json", result));
|
||||
|
||||
// Empty quality value
|
||||
EXPECT_FALSE(
|
||||
detail::parse_accept_header("text/html;q=,application/json", result));
|
||||
@@ -2112,6 +2116,16 @@ TEST(ParseAcceptEncoding5, AcceptEncodingQZeroVariants) {
|
||||
EXPECT_TRUE(ret == detail::EncodingType::None);
|
||||
}
|
||||
|
||||
TEST(ParseAcceptEncodingTest, RejectsTrailingQualityCharacters) {
|
||||
Request req;
|
||||
req.set_header("Accept-Encoding", "gzip;q=0.5junk");
|
||||
|
||||
Response res;
|
||||
res.set_header("Content-Type", "text/plain");
|
||||
|
||||
EXPECT_EQ(detail::EncodingType::None, detail::encoding_type(req, res));
|
||||
}
|
||||
|
||||
TEST(ParseAcceptEncoding6, AcceptEncodingXGzipQZero) {
|
||||
// x-gzip;q=0 should not cause "gzip" to be incorrectly detected
|
||||
Request req;
|
||||
|
||||
Reference in New Issue
Block a user