]> git.kaiwu.me - nginx.git/commitdiff
Disabled HTTP/1.0 requests with Transfer-Encoding.
authorSergey Kandaurov <pluknet@nginx.com>
Mon, 9 Aug 2021 15:12:12 +0000 (18:12 +0300)
committerSergey Kandaurov <pluknet@nginx.com>
Mon, 9 Aug 2021 15:12:12 +0000 (18:12 +0300)
The latest HTTP/1.1 draft describes Transfer-Encoding in HTTP/1.0 as having
potentially faulty message framing as that could have been forwarded without
handling of the chunked encoding, and forbids processing subsequest requests
over that connection: https://github.com/httpwg/http-core/issues/879.

While handling of such requests is permitted, the most secure approach seems
to reject them.

src/http/ngx_http_request.c

index 2d1845d02bff70fdadb1028d52ea7ef1688065c3..bf931bf35d7bb7cec0a7fad81f38e4bc54b9893d 100644 (file)
@@ -1983,6 +1983,14 @@ ngx_http_process_request_header(ngx_http_request_t *r)
     }
 
     if (r->headers_in.transfer_encoding) {
+        if (r->http_version < NGX_HTTP_VERSION_11) {
+            ngx_log_error(NGX_LOG_INFO, r->connection->log, 0,
+                          "client sent HTTP/1.0 request with "
+                          "\"Transfer-Encoding\" header");
+            ngx_http_finalize_request(r, NGX_HTTP_BAD_REQUEST);
+            return NGX_ERROR;
+        }
+
         if (r->headers_in.transfer_encoding->value.len == 7
             && ngx_strncasecmp(r->headers_in.transfer_encoding->value.data,
                                (u_char *) "chunked", 7) == 0)