github yhirose/cpp-httplib v0.60.0

4 hours ago

What's Changed

Security-relevant fixes

  • Use the SAN type in Mbed TLS hostname verification (#2614). Mbed TLS keeps the GeneralName type of a subjectAltName entry apart from its value, and verify_hostname() looked at the value only. A dNSName whose bytes equal an address therefore authenticated that IP host, and an iPAddress or rfc822Name made of printable ASCII was matched as a DNS pattern. An IP host is now matched against iPAddress entries only, and a host name against dNSName entries only. get_cert_sans() looked for the type inside the value, so it returned no entries for an ordinary certificate, or part of a dNSName as an entry of its own. It now returns the DNS, IP, email and URI entries with their types.

Bug fixes

  • Don't resend the request body after a 303 redirect (#2606). A 303 response turns the follow-up request into a GET, but only the buffered body and the headers were cleared. A content provider (sized or chunked) stayed on the request, so the original payload was sent again with the GET, and for a chunked provider the unframed chunks also broke the keep-alive connection.
  • Send the redirect Location path as given (#2607). The path was percent-decoded before the follow-up request, which turned %23, %3F and %25 into a fragment delimiter, a query delimiter and a different octet, so the client requested a different resource than the one named. It also made set_path_encode(false) fail on any Location containing %20.
  • WebSocket subprotocol negotiation:
    • The client accepted any Sec-WebSocket-Protocol value in the handshake response (#2595). A subprotocol the client did not offer now fails the handshake with Error::WebSocketHandshake (RFC 6455 §4.1).
    • The server sent back whatever its SubProtocolSelector returned, even a value outside the client's list. Such a value is now treated as no selection (RFC 6455 §4.2.2).
  • Fix WebSocket pings being sent early on spurious wakeups (#2612). The heartbeat thread waited on its condition variable without a predicate, so a spurious wakeup sent a ping before the ping interval had elapsed. With max_missed_pongs enabled, the early ping also counted toward the pong timeout.
  • SSE client: clear Last-Event-ID on an empty id field (#2611). The client could not tell an empty id field from an event with no id field, so it kept sending the stale ID on reconnect. An empty id now resets it and no Last-Event-ID header is sent.

Documentation

  • README-websocket: note that a SubProtocolSelector return value the client did not propose is ignored.

Full Changelog: v0.59.0...v0.60.0

Don't miss a new cpp-httplib release

NewReleases is sending notifications on new releases.