You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5f55f87
Browse filesBrowse the repository at this point in the historyBrowse files
authored
Join repeated HTTP/1 Cookie lines with "; " (#1386)
* Join repeated HTTP/1 Cookie lines with "; "
_read_headers folded a repeated Cookie line into the previous one with
the appendheader comma, so cookies(req) read Cookie: a=1 and Cookie: b=2
as the single cookie a="1,b=2". Join them with "; " as the HTTP/2
server already does.
* Join repeated Cookie values with "; " in appendheader
appendheader merged a repeated header into the previous entry with a
comma and exempted only Set-Cookie. A Cookie header has no comma list
syntax (RFC 6265 5.4 joins pairs with "; "), so every path that builds
headers through appendheader produced a cookie the server reads as one
pair: Headers(["Cookie" => "a=1", "Cookie" => "b=2"]), mkheaders,
append!, and HTTP.get(url, ["Cookie" => "a=1", "Cookie" => "b=2"]),
which sent Cookie: a="1,b=2". Join Cookie values with "; " there.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* Join received header lines in one pass
Every receive path joined a repeated field line onto the previous entry
with appendheader, which rebuilds the growing value on each line. A peer
that repeats a name made that quadratic: on HTTP/1 a request made of
1 MiB of repeated header lines took about 2.8 s and 16 GiB of
allocation to parse, and the HTTP/2 client, which accepts 10 MiB header
lists, scaled the same way.
The HTTP/1 parser, the HTTP/2 request validator and the HTTP/2 response
header and trailer decoders now store each line as it arrives and join
the section once with _fold_received_fields!, which keeps appendheader's
result and joins every Cookie line into the first with "; " as the
HTTP/2 server did. That also fixes an empty Cookie line followed by
another one: HTTP/1 stored ",b=2", which cookies(req) could not parse,
where HTTP/2 stored "b=2".
The same 1 MiB request now parses in about 0.04 s and 40 MiB.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* Cover consecutive repeats in the fold tests and update a Cookie comment
The HTTP/1 allocation test alternated X-A and Cookie lines, which master
never joined, so it guarded only the global Cookie join. Add a run of
consecutive X-A lines, the shape master parsed in quadratic time, and
check the HTTP/2 trailer decoder the same way as the response decoder.
Move the Cookie appendheader checks into their own testset, and drop the
addcookie! comment that still said appendheader joins with a comma.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Jacob Quinn <quinn.jacobd@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
0 commit comments