Skip to content

HTTP response corrupted with status 400 when URL includes pipe character (|) #27584

Description

@hoangsetup
  • Version: v12.1.0 v12.0.0
  • Platform: MacOS 10.14.2 - Darwin Kernel Version 18.5.0: Mon Mar 11 20:40:32 PDT 2019; root:xnu-4903.251.3~3/RELEASE_X86_64 x8
    6_64

My code:

index.js

var http = require('http');
var url = require('url');

http.createServer(function (req, res) {
  res.writeHead(200, { 'Content-Type': 'text/html' });
  var q = url.parse(req.url, true).query;
  var search = q.search;
  res.end(search);
}).listen(8080);

Starting command: node index.js

Chrome: Version 74.0.3729.131 (Official Build) (64-bit)

When I try to request to my http service, it is working fine with normal url like
http://localhost:8080/?search=example

But, when the url come to http://localhost:8080/?search=example| or http://localhost:8080/?sea|rch=example . My browser gets back This page isn’t working and HTTP ERROR 400 (the request did not appeared on Network tab of Chrome devtool) .

Try again with curl or Postman, these urls are working fine 🤔

=> When I use older node version like v11.11.0 I don't get any errors.

Activity

  1. added
    httpIssues and PRs related to the http subsystem.
    urlIssues and PRs related to the legacy built-in url module.
    on May 6, 2019
  2. added
    http_parserIssues and PRs related to the HTTP parser implementation or http_parser binding.
    and removed
    urlIssues and PRs related to the legacy built-in url module.
    on May 6, 2019
  3. addaleax commented on May 6, 2019

    @addaleax
    Member

    Thank you for reporting this bug! It’s an issue that seems to occur because we switched out the HTTP parser library default in Node 12. The good news is that you can use --http-parser=legacy to work around this issue for now, and get consistent behaviour on both v11.x and v12.x.

  4. addaleax commented on May 6, 2019

    @addaleax
    Member

    Yes, this seems like something that should be fixed in llhttp to me. At least browsers and curl do not percent-encode | in the given example URLs.

    /cc @indutny @nodejs/http

  5. indutny commented on May 6, 2019

    @indutny
    Member

    /me is on it

  6. indutny commented on May 6, 2019

    @indutny
    Member

    🤦 I literally missed this single character. Thank you @hoangsetup for catching this!

  7. indutny commented on May 6, 2019

    @indutny
    Member
  8. added a commit that references this issue on May 7, 2019
  9. added a commit that references this issue on Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    confirmed-bugIssues and PRs for confirmed bugs.httpIssues and PRs related to the http subsystem.http_parserIssues and PRs related to the HTTP parser implementation or http_parser binding.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions