0
Fork 0
mirror of https://github.com/ninenines/cowboy.git synced 2025-07-14 12:20:24 +00:00

204 and 304 responses must not include a body

When calling cowboy_req:reply/4 with a body a crash will occur
resulting in a 500 response. When calling cowboy_req:stream_reply/2,3
and then attempting to send a body a crash will occur.
This commit is contained in:
Loïc Hoguin 2020-05-20 13:41:05 +02:00
parent 8337aca4d3
commit 39b2816255
No known key found for this signature in database
GPG key ID: 8A9DF795F6FED764
4 changed files with 47 additions and 18 deletions

View file

@ -181,6 +181,12 @@ do(<<"reply4">>, Req0, Opts) ->
<<"error">> ->
ct_helper:ignore(erlang, iolist_size, 1),
cowboy_req:reply(200, #{}, ok, Req0);
<<"204body">> ->
ct_helper:ignore(cowboy_req, reply, 4),
cowboy_req:reply(204, #{}, <<"OK">>, Req0);
<<"304body">> ->
ct_helper:ignore(cowboy_req, reply, 4),
cowboy_req:reply(304, #{}, <<"OK">>, Req0);
Status ->
cowboy_req:reply(binary_to_integer(Status), #{}, <<"OK">>, Req0)
end,
@ -199,8 +205,15 @@ do(<<"stream_reply2">>, Req0, Opts) ->
<<"204">> ->
Req = cowboy_req:stream_reply(204, Req0),
{ok, Req, Opts};
<<"304">> ->
<<"204body">> ->
ct_helper:ignore(cowboy_req, stream_body, 3),
Req = cowboy_req:stream_reply(204, Req0),
stream_body(Req),
{ok, Req, Opts};
<<"304body">> ->
ct_helper:ignore(cowboy_req, stream_body, 3),
Req = cowboy_req:stream_reply(304, Req0),
stream_body(Req),
{ok, Req, Opts};
Status ->
Req = cowboy_req:stream_reply(binary_to_integer(Status), Req0),

View file

@ -1886,22 +1886,22 @@ no_body_in_head_response(Config) ->
%1xx responses never include a message body. (RFC7230 3.3)
no_body_in_204_response(Config) ->
doc("204 responses never include a message body. (RFC7230 3.3)"),
doc("204 responses never include a message body. Cowboy produces "
"a 500 error response when attempting to do so. (RFC7230 3.3)"),
Client = raw_open(Config),
ok = raw_send(Client, [
"GET /resp/reply2/204 HTTP/1.1\r\n"
"GET /resp/reply4/204body HTTP/1.1\r\n"
"Host: localhost\r\n"
"\r\n"]),
{_, 204, _, Rest} = cow_http:parse_status_line(raw_recv_head(Client)),
{_, <<>>} = cow_http:parse_headers(Rest),
{error, timeout} = raw_recv(Client, 1, 1000),
{_, 500, _, _} = cow_http:parse_status_line(raw_recv_head(Client)),
ok.
no_body_in_204_response_stream(Config) ->
doc("204 responses never include a message body. (RFC7230 3.3)"),
doc("204 responses never include a message body. Attempting to "
"stream the body produces a crash on the server-side. (RFC7230 3.3)"),
Client = raw_open(Config),
ok = raw_send(Client, [
"GET /resp/stream_reply2/204 HTTP/1.1\r\n"
"GET /resp/stream_reply2/204body HTTP/1.1\r\n"
"Host: localhost\r\n"
"\r\n"]),
{_, 204, _, Rest} = cow_http:parse_status_line(raw_recv_head(Client)),
@ -1910,22 +1910,22 @@ no_body_in_204_response_stream(Config) ->
ok.
no_body_in_304_response(Config) ->
doc("304 responses never include a message body. (RFC7230 3.3)"),
doc("304 responses never include a message body. Cowboy produces "
"a 500 error response when attempting to do so. (RFC7230 3.3)"),
Client = raw_open(Config),
ok = raw_send(Client, [
"GET /resp/reply2/304 HTTP/1.1\r\n"
"GET /resp/reply4/304body HTTP/1.1\r\n"
"Host: localhost\r\n"
"\r\n"]),
{_, 304, _, Rest} = cow_http:parse_status_line(raw_recv_head(Client)),
{_, <<>>} = cow_http:parse_headers(Rest),
{error, timeout} = raw_recv(Client, 1, 1000),
{_, 500, _, _} = cow_http:parse_status_line(raw_recv_head(Client)),
ok.
no_body_in_304_response_stream(Config) ->
doc("304 responses never include a message body. (RFC7230 3.3)"),
doc("304 responses never include a message body. Attempting to "
"stream the body produces a crash on the server-side. (RFC7230 3.3)"),
Client = raw_open(Config),
ok = raw_send(Client, [
"GET /resp/stream_reply2/304 HTTP/1.1\r\n"
"GET /resp/stream_reply2/304body HTTP/1.1\r\n"
"Host: localhost\r\n"
"\r\n"]),
{_, 304, _, Rest} = cow_http:parse_status_line(raw_recv_head(Client)),