Add CRLF injection protection for header values
Implement security validation to prevent HTTP header injection attacks: - Reject header values containing \r or \n characters - Add comprehensive test coverage for CRLF protection - Replace multiline YAML test with proper rejection test Security improvements: - Validates header values to prevent header injection - Clear warning messages when values are rejected - Four new test cases covering LF, CR, CRLF, and multiline scenarios This addresses a critical security concern where malicious headers could be injected via newline characters in header values. All 84 tests passing.
This commit is contained in:
+5
@@ -61361,6 +61361,11 @@ function validateAndMaskHeaders(headers) {
|
||||
}
|
||||
// Convert value to string
|
||||
const stringValue = String(value);
|
||||
// Validate header value to prevent CRLF/header injection
|
||||
if (stringValue.includes('\r') || stringValue.includes('\n')) {
|
||||
coreExports.warning(`Skipping header "${name}" because its value contains newline characters, which are not allowed in HTTP header values.`);
|
||||
continue;
|
||||
}
|
||||
validHeaders[name] = stringValue;
|
||||
// Mask sensitive headers in logs
|
||||
const lowerName = name.toLowerCase();
|
||||
|
||||
+1
-1
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user