Skip to content

Conversation

@mcollina
Copy link
Member

@mcollina mcollina commented Jan 5, 2026

Summary

  • Added security warning to strictContentLength documentation in Client.md and H2CClient.md
  • Documents risks of disabling this option: HTTP Request Smuggling attacks, cache poisoning, credential hijacking, and bypassing security controls
  • Recommends only disabling in controlled environments with trusted request sources

Test plan

  • Verify documentation renders correctly in markdown

🤖 Generated with Claude Code

Document security implications of disabling strictContentLength, including
HTTP Request Smuggling attacks, cache poisoning, credential hijacking, and
bypassing security controls.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Signed-off-by: Matteo Collina <hello@matteocollina.com>
@codecov-commenter
Copy link

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.87%. Comparing base (d560767) to head (1fce116).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4726   +/-   ##
=======================================
  Coverage   92.86%   92.87%           
=======================================
  Files         109      109           
  Lines       33809    33818    +9     
=======================================
+ Hits        31398    31407    +9     
  Misses       2411     2411           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.
Copy link
Contributor

@Uzlopak Uzlopak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Uzlopak Uzlopak merged commit fbbe283 into main Jan 6, 2026
33 of 35 checks passed
@Uzlopak Uzlopak deleted the docs/strict-content-length-security-warning branch January 6, 2026 09:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants