haskell-servant / haskell-servant/servant

Invalid HTTP headers

Open
#770 7 comments 0 reactions 0 assignees View on GitHub
help wanted
Dominant language
Haskell
Stars
2k
Forks
427
Avg merge
2d 23h
Merged PRs (30d)
5

Description

I'm not sure if there's a type-safe way of enforcing valid HTTP header names, but `servant` currently allows header names to have spaces which can break break Chrome.

More information can be found in a `wai` issue at https://github.com/yesodweb/wai/issues/628.

### Example

```
{-# LANGUAGE DataKinds #-}
{-# LANGUAGE OverloadedStrings #-}
{-# LANGUAGE TypeOperators #-}

module Main where

import Network.Wai
import Network.Wai.Handler.Warp
import Servant
import Data.Text

type HelloAPI = Get '[PlainText] (Headers '[Header "A A" Text] Text)

server :: Server HelloAPI
server = return $ addHeader "foo" $ "Hello, world!"

helloApi :: Proxy HelloAPI
helloApi = Proxy

app :: Application
app = serve helloApi server

main :: IO ()
main = run 80 app
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.