Middleware to validate response headers.
Modulewai-extra-3.1.16Haskell2010
Network.Wai.Middleware.ValidateHeaders
This module provides a middleware to validate response headers. RFC 9110 constrains the allowed octets in header names and values:
Header names are tokens, i.e. visible ASCII characters (octets 33 to 126 inclusive) except delimiters.
Header values should be limited to visible ASCII characters, the whitespace characters space and horizontal tab and octets 128 to 255. Headers values may not have trailing whitespace (see RFC 9110 Section 5.5). Folding is not allowed.
validateHeadersMiddleware enforces these constraints for response headers by responding with a 500 Internal Server Error when an offending character is present. This is meant to catch programmer errors early on and reduce attack surface.
- 3 types
- 2 values
- Packagewai-extra-3.1.16
- Exports5
- LanguageHaskell2010
- LicenceMIT
- SourceValidateHeaders.hs
Middleware
1 declarationSettings
2 declarationsConfiguration for validateHeadersMiddleware.
Constructors
ValidateHeadersSettingsonInvalidHeader :: InvalidHeader -> MiddlewareCalled when an invalid header is present.
Default configuration for validateHeadersMiddleware. Checks that each header meets the requirements listed at the top of this module: Allowed octets for name and value and no trailing whitespace in the value.
Types
2 declarationsDescription of an invalid header.
Constructors
Reasons a header might be invalid.
Constructors
InvalidOctetInHeaderName Word8Header name contains an invalid octet.
InvalidOctetInHeaderValue Word8Header value contains an invalid octet.
TrailingWhitespaceInHeaderValueHeader value contains trailing whitespace.