Repository navigation
fix(custom-headers): reject non-ASCII characters in header values (CLI-31G) - #1660
Open
sentry[bot] wants to merge 2 commits into
Open
sentry[bot] wants to merge 2 commits into
sentry[bot] wants to merge 2 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds validation for custom HTTP header values to prevent
TypeError: Cannot convert argument to a ByteStringwhen non-Latin-1 characters (like emojis or other Unicode symbols), carriage returns, line feeds, or null characters are present.Previously, custom header values were not checked for ByteString compliance before being passed to
undici'sHeaders.set(). This could lead to a runtimeTypeErrorcrash if a user configured a custom header with an invalid character.The
assertValidHeaderValuefunction is introduced insrc/lib/custom-headers.tsto perform this validation. It is called by bothparseCustomHeaders(forSENTRY_CUSTOM_HEADERSenv var and stored defaults) andsetCustomHeadersOverride(forcreateSentrySDK({ headers })). Invalid values now result in aConfigErrorbeing thrown early, providing a clearer error message to the user and preventing the underlying HTTP client crash.Note: This issue (CLI-31G) was also caused by unvalidated authentication tokens containing non-ASCII characters. That specific problem is addressed by commit
980fa503(#1638), which is already onmainand will be released in 0.46.0 (or backported to a 0.45.x patch).An existing e2e test (
test/e2e/auth.test.ts) that previously relied on theTypeErrorcrash for credential redaction testing has been updated to expect the newConfigErrorbehavior.Fixes CLI-31G
@sentry <feedback>: Autofix iterates on these changes@sentry stop iterating: Autofix stops iterating on this runThis PR was automatically generated by Sentry. You can adjust this setting at any time.