Fix XMLHttpRequest.setRequestHeader to append duplicate headers per spec - #56394
Fix XMLHttpRequest.setRequestHeader to append duplicate headers per spec#56394zmunm wants to merge 2 commits into
Conversation
Add tests verifying XHR spec compliance for setRequestHeader: - Same header called multiple times should append with ', ' - Case-insensitive header name merging - Throw when called before open() These tests currently FAIL, exposing the spec violation.
Comply with XHR Living Standard 4.5.2: when setRequestHeader is called multiple times with the same header, append with ', ' instead of overwriting.
|
Hi @zmunm! Thank you for your pull request and welcome to our community. Action RequiredIn order to merge any pull request (code, docs, etc.), we require contributors to sign our Contributor License Agreement, and we don't seem to have one on file for you. ProcessIn order for us to review and merge your suggested changes, please sign at https://code.facebook.com/cla. If you are contributing on behalf of someone else (eg your employer), the individual CLA may not be sufficient and your employer may need to sign the corporate CLA. Once the CLA is signed, our tooling will perform checks and validations. Afterwards, the pull request will be tagged with If you have received this in error or have any questions, please contact us at cla@meta.com. Thanks! |
|
Thank you for signing our Contributor License Agreement. We can now accept your code for this (and any) Meta Open Source project. Thanks! |
|
@fabriziocucci has imported this pull request. If you are a Meta employee, you can view this in D100144689. |
Summary: `XMLHttpRequest.setRequestHeader()` overwrites the previous value when called multiple times with the same header name. Per the [XHR Living Standard §4.5.2](https://xhr.spec.whatwg.org/#the-setrequestheader()-method), duplicate headers should be appended with `, `. Real-world example: [Sentry JS SDK assumes append behavior](https://github.com/getsentry/sentry-javascript/blob/10.38.0/packages/browser/src/tracing/request.ts#L440-L445) when setting the `baggage` header, which causes previously set baggage values to be silently dropped on React Native. ## Changelog: <!-- Help reviewers and the release process by writing your own changelog entry. Pick one each for the category and type tags: [ANDROID|GENERAL|IOS|INTERNAL] [BREAKING|ADDED|CHANGED|DEPRECATED|REMOVED|FIXED|SECURITY] - Message For more details, see: https://reactnative.dev/contributing/changelogs-in-pull-requests --> [GENERAL] [FIXED] - Fix XMLHttpRequest.setRequestHeader to append duplicate headers per spec > **Note:** This is technically a breaking change for code that relied on the previous overwrite behavior (e.g., calling `setRequestHeader` twice to replace a value). However, that behavior was non-compliant with the XHR spec, so such code should use a single call with the desired final value instead. X-link: #56394 Reviewed By: huntie, cipolleschi Differential Revision: D100144689 Pulled By: fabriziocucci fbshipit-source-id: 0697d88e02f76285ff50e339b0c25cda8337c36c
Summary:
XMLHttpRequest.setRequestHeader()overwrites the previous value when called multiple times with the same header name. Per the XHR Living Standard §4.5.2, duplicate headers should be appended with,.Real-world example: Sentry JS SDK assumes append behavior
when setting the
baggageheader, which causes previously set baggage values to be silently dropped on React Native.Changelog:
[GENERAL] [FIXED] - Fix XMLHttpRequest.setRequestHeader to append duplicate headers per spec
Test Plan:
Unit tests — 3 tests added in
XMLHttpRequest-test.js:open()Run the snippet below in both browser DevTools and RN debugger console to compare: