exclude connection header in response passThrough#3602
Merged
hueniverse merged 1 commit intoOct 18, 2017
Merged
Conversation
Contributor
|
If you want to be thorough, there are a several other headers that need to go as well, like These are listed nicely in the deprecated https://www.w3.org/Protocols/rfc2616/rfc2616-sec13.html#sec13.5.1. Additionally, you need to remove any headers listed in the value of the connection header according to the current RFC: https://tools.ietf.org/html/rfc7230#section-6.1. |
|
This thread has been automatically locked due to inactivity. Please open a new issue for related bugs or questions following the new issue template instructions. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When a hapi.js server is acting as a proxy or gateway, and a handler calls the reply/responder interface with a stream that is an IncomingMessage from an upstream, I believe the default behavior of the passThrough mode should be to not copy the connection header.
The semantics of the Connection header are that it represents per-hop connection options, and that a proxy or gateway MUST remove any connection options before forwarding a message (in this case a response to its client). Basically connection options (usually keep-alive or close) should be negotiated between the server/client and between the server/upstream independent of each other.
The semantics of the Connection header are actually a little more complicated than that, because the header is supposed to be able to container tokens representing other headers that are per-hop. But I do not have that use case myself, so I did not undertake to implement that.