Skip to content

fix(fetch): reject forbidden HTTP methods CONNECT, TRACE, and TRACK#5203

Open
HiteshShonak wants to merge 2 commits intoboa-dev:mainfrom
HiteshShonak:fix/request-forbidden-methods
Open

fix(fetch): reject forbidden HTTP methods CONNECT, TRACE, and TRACK#5203
HiteshShonak wants to merge 2 commits intoboa-dev:mainfrom
HiteshShonak:fix/request-forbidden-methods

Conversation

@HiteshShonak
Copy link
Contributor

This Pull Request fixes/closes #5202.

It changes the following:

  • Reject CONNECT, TRACE, and TRACK methods in the Request constructor and throw a TypeError, matching the Fetch Standard.
  • Check is case-insensitive, so connect, trace, track are also rejected.
  • Added regression tests for all three forbidden methods.

Testing:

cargo test -p boa_runtime request -- --nocapture

Spec reference: https://fetch.spec.whatwg.org/#forbidden-method

@HiteshShonak HiteshShonak requested a review from a team as a code owner March 21, 2026 04:37
Copilot AI review requested due to automatic review settings March 21, 2026 04:37
@github-actions github-actions bot added Waiting On Review Waiting on reviews from the maintainers C-Tests Issues and PRs related to the tests. C-Runtime Issues and PRs related to Boa's runtime features and removed Waiting On Review Waiting on reviews from the maintainers labels Mar 21, 2026
@github-actions github-actions bot added this to the v1.0.0 milestone Mar 21, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates Boa’s Fetch Request implementation to match the Fetch Standard by rejecting forbidden HTTP methods (CONNECT, TRACE, TRACK) in the Request constructor path, and adds regression tests to prevent the behavior from regressing.

Changes:

  • Reject CONNECT/TRACE/TRACK (case-insensitive) in RequestInit::into_request_builder by throwing a TypeError.
  • Add regression tests asserting new Request(..., { method }) throws for each forbidden method.
  • Add indoc usage in request tests for cleaner embedded JS snippets.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
core/runtime/src/fetch/request.rs Adds forbidden-method validation during request builder construction, returning a TypeError for CONNECT/TRACE/TRACK.
core/runtime/src/fetch/tests/request.rs Adds new tests ensuring Request construction throws when using forbidden methods.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions
Copy link

github-actions bot commented Mar 21, 2026

Test262 conformance changes

Test result main count PR count difference
Total 52,963 52,963 0
Passed 50,539 50,539 0
Ignored 1,426 1,426 0
Failed 998 998 0
Panics 2 2 0
Conformance 95.42% 95.42% 0.00%

Tested main commit: 58a24587890677d94618259dfaa5f257ab5ef9c9
Tested PR commit: 3190e5e6986b17df1c4e23dce597f413388bd3d8
Compare commits: 58a2458...3190e5e

@codecov
Copy link

codecov bot commented Mar 21, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 59.81%. Comparing base (6ddc2b4) to head (3190e5e).
⚠️ Report is 913 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##             main    #5203       +/-   ##
===========================================
+ Coverage   47.24%   59.81%   +12.56%     
===========================================
  Files         476      582      +106     
  Lines       46892    63466    +16574     
===========================================
+ Hits        22154    37961    +15807     
- Misses      24738    25505      +767     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions github-actions bot added the Waiting On Review Waiting on reviews from the maintainers label Mar 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

C-Runtime Issues and PRs related to Boa's runtime features C-Tests Issues and PRs related to the tests. Waiting On Review Waiting on reviews from the maintainers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Request constructor accepts forbidden HTTP methods like CONNECT, TRACE, and TRACK

2 participants