fix(res.set): prevent Content-Type from being set to 'false' for unknown types#7128
Closed
cyphercodes wants to merge 1 commit intoexpressjs:masterfrom
Closed
fix(res.set): prevent Content-Type from being set to 'false' for unknown types#7128cyphercodes wants to merge 1 commit intoexpressjs:masterfrom
cyphercodes wants to merge 1 commit intoexpressjs:masterfrom
Conversation
…own types
When res.set('Content-Type', value) is called with an unknown type,
mime.contentType() returns false. Previously, this false value was
passed to setHeader, which coerced it to the string 'false'.
This fix checks if mime.contentType() returns false and falls back
to the original value instead, consistent with how res.type() handles
unknown types.
Fixes expressjs#7034
Contributor
|
Duplicate of #7035 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
When calling
res.set('Content-Type', value)where the value doesn't contain a/(like a bare extension or shorthand),mime.contentType(value)is used to resolve the full MIME type. However, ifmime.contentType()returnsfalse(for unrecognized types), the Content-Type header is set to the literal string"false"instead of keeping the original value.Reproduction
Requesting
/returnsContent-Type: falsein the response headers.Root Cause
In
res.set()(response.js), the Content-Type branch does:When
mime.contentType(value)returnsfalse, the valuefalseis passed tosetHeader, which coerces it to the string"false".Solution
This fix checks if
mime.contentType()returnsfalseand falls back to the original value instead:This is consistent with how
res.type()handles unknown types.Changes
lib/response.jsto handle the case whenmime.contentType()returnsfalsetest/res.set.jsto verify the fixFixes #7034