mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-02 05:22:46 +07:00
write_request_line checked the request target for CR/LF but concatenated the method verbatim. A method carrying CR/LF could smuggle a whole request ahead of the real one, and the client would take the smuggled request's response as its own. A method with a space or an empty method put a malformed request line on the wire. Require the method to be a token (RFC 9110 Section 9.1) before anything is written. All three callers (the buffered client path, open_stream and the WebSocket handshake) go through this function and fail with Error::Write, as they already do for a rejected target. Claude-Session: https://claude.ai/code/session_01NTDesJQTQPEuu4o4XCu69g