Conversation
|
Review requested:
|
Add non-throwing counterparts of http.validateHeaderName() and
http.validateHeaderValue() that return a boolean instead of throwing.
Rejecting an invalid header with the existing validators costs a few
microseconds, because an error object and its stack trace are created,
compared to ~20ns for the boolean check. Userland HTTP implementations
such as undici (fetch Headers, request options) therefore keep private
copies of the token and field-value tables from _http_common. These new
functions let them reuse the core implementation.
isValidHeaderValue() accepts an optional `httpValidation` option
('strict' or 'relaxed') that has the same meaning as the option of the
same name on http.createServer() and http.request().
Signed-off-by: James M Snell <jasnell@gmail.com>
Compare http.isValidHeaderName() and http.isValidHeaderValue() with http.validateHeaderName() and http.validateHeaderValue() wrapped in try/catch, for valid and invalid input, and for both 'strict' and 'relaxed' header value validation. Signed-off-by: James M Snell <jasnell@gmail.com>
125da84 to
1b50a1d
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #66334 +/- ##
==========================================
- Coverage 90.37% 90.36% -0.02%
==========================================
Files 792 792
Lines 275324 275368 +44
Branches 52764 52770 +6
==========================================
+ Hits 248828 248834 +6
- Misses 16918 16960 +42
+ Partials 9578 9574 -4
🚀 New features to boost your workflow:
|
Commit Queue failedThis pull request has multiple commits, but no landing policy was selected. Add
commit-queue-squash
The pull request was removed from the Commit Queue and labeled
commit-queue-failed
Full Commit Queue output |
Add non-throwing counterparts of http.validateHeaderName() and
http.validateHeaderValue() that return a boolean instead of throwing.
Rejecting an invalid header with the existing validators costs a few
microseconds, because an error object and its stack trace are created,
compared to ~20ns for the boolean check. Userland HTTP implementations
such as undici (fetch Headers, request options) therefore keep private
copies of the token and field-value tables from _http_common. These new
functions let them reuse the core implementation.
isValidHeaderValue() accepts an optional `httpValidation` option
('strict' or 'relaxed') that has the same meaning as the option of the
same name on http.createServer() and http.request().
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #66334
Reviewed-By: Filip Skokan <panva.ip@gmail.com>
Reviewed-By: Tim Perry <pimterry@gmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Compare http.isValidHeaderName() and http.isValidHeaderValue() with http.validateHeaderName() and http.validateHeaderValue() wrapped in try/catch, for valid and invalid input, and for both 'strict' and 'relaxed' header value validation. Signed-off-by: James M Snell <jasnell@gmail.com> PR-URL: #66334 Reviewed-By: Filip Skokan <panva.ip@gmail.com> Reviewed-By: Tim Perry <pimterry@gmail.com> Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
|
Landed in 3a30bca...296584b |
Add non-throwing counterparts of http.validateHeaderName() and
http.validateHeaderValue() that return a boolean instead of throwing.
Rejecting an invalid header with the existing validators costs a few
microseconds rather than ~20ns for the boolean check. libraries like
undicikeep private copies of the token and field-value tables from_http_common. This allows them to reuse the core implementations.Keep in mind, this is mostly to improve the performance of the invalid
path.