New issue
Advanced search Search tips

Issue 903419 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Nov 9
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Signed Exchange: stateful request header sec-webSocket-key not being blocked

Project Member Reported by twif...@google.com, Nov 8

Issue description

I haven't confirmed this with a test case, but https://cs.chromium.org/chromium/src/content/browser/web_package/signed_exchange_envelope.cc?l=36&rcl=4e5b2c2c758ced0ab5de2f67dc909dc16950e33c contains an uppercase character, while the function's input is lowercase.
 
Owner: kouhei@chromium.org
Thanks. CL: https://chromium-review.googlesource.com/c/chromium/src/+/1328061
Project Member

Comment 2 by bugdroid1@chromium.org, Nov 9

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/a78d541602c264218c549a2135b5623c591f3672

commit a78d541602c264218c549a2135b5623c591f3672
Author: Kouhei Ueno <kouhei@chromium.org>
Date: Fri Nov 09 03:11:01 2018

sec-websocket-key should be lowercased

Author: twifkak@chromium.org
Bug:  903419 
Change-Id: I2dd5e05c993cd70886035b681ffb70ed29df39c0
Reviewed-on: https://chromium-review.googlesource.com/c/1328061
Reviewed-by: Kunihiko Sakamoto <ksakamoto@chromium.org>
Reviewed-by: Devin Mullins <twifkak@chromium.org>
Reviewed-by: Kinuko Yasuda <kinuko@chromium.org>
Reviewed-by: Tsuyoshi Horo <horo@chromium.org>
Commit-Queue: Kouhei Ueno <kouhei@chromium.org>
Cr-Commit-Position: refs/heads/master@{#606720}
[modify] https://crrev.com/a78d541602c264218c549a2135b5623c591f3672/content/browser/web_package/signed_exchange_envelope.cc

Status: Started (was: Untriaged)
Status: Fixed (was: Started)

Sign in to add a comment