haskell / haskell/HTTP

receiveHTTP does not preprocess the incoming URI before it is parsed

Open
#76 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Haskell
Stars
186
Forks
59
PR merge metrics
No merged PRs in 30d

Description

Because of the strict parsing of URIs by Network.URI.parseURIReference, parseRequestHead fails on this "almost valid" URI:

```
ghci> parseRequestHead ["GET http://fonts.googleapis.com/css?family=Roboto:300|Open+Sans:700|Open+Sans:300&lang=en HTTP/1.1"]
ghci> Left (ErrorParse "parseRequestHead Request command line parse failure: GET http://fonts.googleapis.com/css?family=Roboto:300|Open+Sans:700|Open+Sans:300&lang=en HTTP/1.1")
```

Replacing the pipe characters with %7C allows the URI to parse.

receiveHTTP, or maybe parseRequestHead, should probably try to escape the characters that are considered invalid for URIs, before sending the string through parseURIReference.

In that regard, `escapeURIString isAllowedInURI` from Network.URI may be handy.

(Something about "be conservative in what you send, be liberal in what you accept" prompted me to raise this issue.)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading receiveHTTP and parseRequestHead, then inspect how the incoming request URI reaches Network.URI.parseURIReference. Check the suggested escapeURIString isAllowedInURI behavior for invalid URI characters, and consider both entry points named in the issue. Done means the shown URI is accepted while already valid URIs continue to parse correctly.

Written by the indexing model from the issue text.

Assessment

Tech stack
haskell
Domain
networking
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.