haskell-servant / haskell-servant/servant
Invalid HTTP headers
- Dominant language
- Haskell
- Stars
- 2k
- Forks
- 427
- Avg merge
- 2d 23h
- Merged PRs (30d)
- 5
Description
I'm not sure if there's a type-safe way of enforcing valid HTTP header names, but `servant` currently allows header names to have spaces which can break break Chrome.
More information can be found in a `wai` issue at https://github.com/yesodweb/wai/issues/628.
### Example
```
{-# LANGUAGE DataKinds #-}
{-# LANGUAGE OverloadedStrings #-}
{-# LANGUAGE TypeOperators #-}
module Main where
import Network.Wai
import Network.Wai.Handler.Warp
import Servant
import Data.Text
type HelloAPI = Get '[PlainText] (Headers '[Header "A A" Text] Text)
server :: Server HelloAPI
server = return $ addHeader "foo" $ "Hello, world!"
helloApi :: Proxy HelloAPI
helloApi = Proxy
app :: Application
app = serve helloApi server
main :: IO ()
main = run 80 app
```
Contributor guide
Assessment
This issue has not been assessed yet.