node/test/parallel/test-http2-single-headers-validation.js
Tim Perry 0fccfa421b
http2: add strictSingleValueFields option to relax header validation
Previously it was impossible to send multiple values for any header
or trailer defined officially as supporting only a single value.

This is a good default, but in practice many of these headers are used
in weird & wonderful ways where this can be problematic. This new
option allows for relaxing this restriction to support those cases
where required.

This option defaults to true so validation will still be applied
as before, rejecting multiple single-value fields, unless explicitly
disabled.

PR-URL: https://github.com/nodejs/node/pull/59917
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
2026-02-21 22:58:52 +00:00

52 lines
1.2 KiB
JavaScript

'use strict';
const common = require('../common');
if (!common.hasCrypto)
common.skip('missing crypto');
const assert = require('assert');
const http2 = require('http2');
const server = http2.createServer();
// Each of these headers must appear only once
const singles = [
'content-type',
'user-agent',
'referer',
'authorization',
'proxy-authorization',
'if-modified-since',
'if-unmodified-since',
'from',
'location',
'max-forwards',
];
server.on('stream', common.mustNotCall());
server.listen(0, common.mustCall(() => {
const client = http2.connect(`http://localhost:${server.address().port}`);
for (const i of singles) {
assert.throws(
() => client.request({ [i]: 'abc', [i.toUpperCase()]: 'xyz' }),
{
code: 'ERR_HTTP2_HEADER_SINGLE_VALUE',
name: 'TypeError',
message: `Header field "${i}" must only have a single value`
}
);
assert.throws(
() => client.request({ [i]: ['abc', 'xyz'] }),
{
code: 'ERR_HTTP2_HEADER_SINGLE_VALUE',
name: 'TypeError',
message: `Header field "${i}" must only have a single value`
}
);
}
server.close();
client.close();
}));