mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-01 05:02:29 +07:00
* Reject a Range first-byte-pos that overflows ssize_t parse_range_header initializes first to the -1 sentinel that means "no first-byte-pos" and only overwrites it when detail::from_chars succeeds. On std::errc::result_out_of_range the assignment is skipped and -1 survives, so "bytes=9223372036854775808-100" is parsed as the suffix range "bytes=-100" and range_error serves the last 100 bytes instead of returning 416. Before the parser was rewritten onto detail::from_chars, std::stoll threw std::out_of_range on the same input, the catch arm added in 8f8761e for issue #705 returned false, and the request was answered with 416. The catch arm is still there but from_chars reports through an error code, so nothing reaches it any more. get_header_value_u64 and parse_port already reject an out-of-range value at their from_chars call sites; this was the remaining one that dropped the error. The last-byte-pos side is deliberately unchanged: -1 there is the documented RFC 9110 14.1.2 "remainder of the representation" value, so an oversized last-byte-pos stays accepted. * Simplify the Range first-byte-pos overflow check Parse the first-byte-pos straight into first, since a failed parse now returns before first is read, and fold the overflow test into the existing batch of rejected ranges. Also note on the last-byte-pos side why an overflow there deliberately keeps -1. Claude-Session: https://claude.ai/code/session_01JYPWKpbp4a881EdpEf2xSi --------- Co-authored-by: yhirose <yuji.hirose.bug@gmail.com>