Skip to content

fix(fixRequestBody): harden form-data stringification - #1260

Merged
chimurai merged 3 commits into
masterfrom
fix-request-body-form-data-fix
Jun 14, 2026
Merged

chimurai merged 3 commits into
masterfrom
fix-request-body-form-data-fix

Conversation

@chimurai

@chimurai chimurai commented Jun 14, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

Release Notes

  • Bug Fixes

    • Hardened form-data serialization to prevent header and body injection attacks by validating multipart boundaries and sanitizing field names and values.
    • Improved error handling and HTTP status code mapping for form-data processing failures, ensuring proper error responses.
  • Internal Improvements

    • Enhanced error handling infrastructure for HTTP proxy middleware.

@coderabbitai

coderabbitai Bot commented Jun 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 064bf90d-19a1-4f93-b51a-d106a1946dd8

📥 Commits

Reviewing files that changed from the base of the PR and between 013dd9b and 382a5a6.

📒 Files selected for processing (8)
  • CHANGELOG.md
  • src/errors.ts
  • src/handlers/fix-request-body-utils/stringify-form-data.ts
  • src/handlers/fix-request-body.ts
  • src/status-code.ts
  • test/e2e/http-proxy-middleware.spec.ts
  • test/unit/fix-request-body-utils/stringify-form-data.spec.ts
  • test/unit/fix-request-body.spec.ts

📝 Walkthrough

Walkthrough

A new HttpProxyMiddlewareError class is introduced, and a hardened stringifyFormData utility is added that parses the multipart boundary, validates field names and values for CR/LF and boundary-delimiter injection, and escapes field names. fixRequestBody switches to this utility and wraps all body-rewrite logic in a try/catch that destroys the proxy request on failure. getStatusCode is updated to map HPM_ERR_INVALID_MULTIPART_* codes to HTTP 400.

Changes

Multipart Form-Data Security Hardening

Layer / File(s) Summary
HttpProxyMiddlewareError class
src/errors.ts
Exports HttpProxyMiddlewareError extends Error with a code instance field, runtime name alignment, and optional V8 stack capture — the shared error contract for multipart validation failures.
stringifyFormData utility with injection guards
src/handlers/fix-request-body-utils/stringify-form-data.ts
Implements boundary extraction with legacy fallback, CR/LF and boundary-delimiter injection validation on field names and values, field-name escaping for Content-Disposition, and multipart body assembly; throws HttpProxyMiddlewareError with distinct codes on each violation.
fixRequestBody wiring and HTTP 400 status mapping
src/handlers/fix-request-body.ts, src/status-code.ts
Replaces the inline multipart serializer with stringifyFormData, wraps all body-rewrite branches in try/catch calling proxyReq.destroy(toError(error)) on failure, adds toError helper, and updates getStatusCode to return 400 immediately for HPM_ERR_INVALID_MULTIPART_* error codes.
Unit tests, E2E test, and changelog
test/unit/fix-request-body-utils/stringify-form-data.spec.ts, test/unit/fix-request-body.spec.ts, test/e2e/http-proxy-middleware.spec.ts, CHANGELOG.md
Covers boundary parsing variants, field serialization, all security rejection paths with specific error codes, unsafe multipart inputs in the handler, quote escaping, and a full E2E CRLF injection scenario asserting HTTP 400 and no target invocation.

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant fixRequestBody
  participant stringifyFormData
  participant proxyReq
  participant getStatusCode

  Client->>fixRequestBody: POST multipart/form-data body
  fixRequestBody->>stringifyFormData: contentType, parsed body data
  alt boundary or field is invalid (CR/LF or delimiter injection)
    stringifyFormData-->>fixRequestBody: throws HttpProxyMiddlewareError(HPM_ERR_INVALID_MULTIPART_*)
    fixRequestBody->>proxyReq: destroy(toError(error))
    proxyReq->>getStatusCode: error.code matches HPM_ERR_INVALID_MULTIPART_
    getStatusCode-->>Client: HTTP 400
  else valid multipart data
    stringifyFormData-->>fixRequestBody: serialized multipart body string
    fixRequestBody->>proxyReq: write(body)
  end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐇 A sneaky CRLF tried to slip through the gate,
But the rabbit said "No! That body's not straight!"
With boundaries parsed and each field name escaped,
Injections rejected — the form-data shaped.
HttpProxyMiddlewareError now codes every sin,
And HTTP 400 keeps the bad data out! 🥕

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 28.57% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically describes the main change: hardening form-data stringification in the fixRequestBody handler through improved security validations.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-request-body-form-data-fix

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-new Bot commented Jun 14, 2026

Copy link
Copy Markdown
npm i https://pkg.pr.new/http-proxy-middleware@1260

commit: 382a5a6

@coveralls

Copy link
Copy Markdown

Coverage Status

coverage: 95.238% (+0.3%) from 94.915% — fix-request-body-form-data-fix into master

@chimurai
chimurai merged commit a1ac315 into master Jun 14, 2026
26 checks passed
@chimurai
chimurai deleted the fix-request-body-form-data-fix branch June 14, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants