fix(fixRequestBody): harden form-data stringification - #1260
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (8)
📝 WalkthroughWalkthroughA new ChangesMultipart Form-Data Security Hardening
Sequence Diagram(s)sequenceDiagram
participant Client
participant fixRequestBody
participant stringifyFormData
participant proxyReq
participant getStatusCode
Client->>fixRequestBody: POST multipart/form-data body
fixRequestBody->>stringifyFormData: contentType, parsed body data
alt boundary or field is invalid (CR/LF or delimiter injection)
stringifyFormData-->>fixRequestBody: throws HttpProxyMiddlewareError(HPM_ERR_INVALID_MULTIPART_*)
fixRequestBody->>proxyReq: destroy(toError(error))
proxyReq->>getStatusCode: error.code matches HPM_ERR_INVALID_MULTIPART_
getStatusCode-->>Client: HTTP 400
else valid multipart data
stringifyFormData-->>fixRequestBody: serialized multipart body string
fixRequestBody->>proxyReq: write(body)
end
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
Summary by CodeRabbit
Release Notes
Bug Fixes
Internal Improvements