| Index: Source/platform/network/HTTPParsers.cpp
|
| diff --git a/Source/platform/network/HTTPParsers.cpp b/Source/platform/network/HTTPParsers.cpp
|
| index 29b7f5f2d128c47d16a63d16e8498d44dd6b0352..216ab8441620a9b166d9a3537a607416d0c1b980 100644
|
| --- a/Source/platform/network/HTTPParsers.cpp
|
| +++ b/Source/platform/network/HTTPParsers.cpp
|
| @@ -107,21 +107,33 @@ static inline bool skipValue(const String& str, unsigned& pos)
|
| return pos != start;
|
| }
|
|
|
| -bool isValidHTTPHeaderValue(const String& name)
|
| +// See RFC 7230, Section 3.2.3.
|
| +bool isValidHTTPHeaderValue(const String& value)
|
| {
|
| - // FIXME: This should really match name against
|
| - // field-value in section 4.2 of RFC 2616.
|
| + UChar c = value[0];
|
| + if (c == ' ' || c == '\t')
|
| + return false;
|
| +
|
| + c = value[value.length() - 1];
|
| + if (c == ' ' || c == '\t')
|
| + return false;
|
|
|
| - return name.containsOnlyLatin1() && !name.contains('\r') && !name.contains('\n') && !name.contains(static_cast<UChar>('\0'));
|
| + for (unsigned i = 0; i < value.length(); ++i) {
|
| + c = value[i];
|
| + if (c == 0x7F || c > 0xFF || (c < 0x20 && c != '\t'))
|
| + return false;
|
| + }
|
| +
|
| + return true;
|
| }
|
|
|
| -// See RFC 2616, Section 2.2.
|
| -bool isValidHTTPToken(const String& characters)
|
| +// See RFC 7230, Section 3.2.6.
|
| +bool isValidHTTPToken(const String& value)
|
| {
|
| - if (characters.isEmpty())
|
| + if (value.isEmpty())
|
| return false;
|
| - for (unsigned i = 0; i < characters.length(); ++i) {
|
| - UChar c = characters[i];
|
| + for (unsigned i = 0; i < value.length(); ++i) {
|
| + UChar c = value[i];
|
| if (c <= 0x20 || c >= 0x7F
|
| || c == '(' || c == ')' || c == '<' || c == '>' || c == '@'
|
| || c == ',' || c == ';' || c == ':' || c == '\\' || c == '"'
|
|
|