From a391e95bcb74c702089157b1076a477620d1af57 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Mon, 16 Mar 2026 17:53:08 +0800 Subject: [PATCH] fix(test): avoid unhandled header injection rejection --- test/features/security.test.js | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/test/features/security.test.js b/test/features/security.test.js index 04be258..6c36700 100644 --- a/test/features/security.test.js +++ b/test/features/security.test.js @@ -180,18 +180,14 @@ describe('Security Features', () => { }, 20000); it('should handle header injection attempts', async () => { - // Headers with CRLF injection should be rejected by the runtime - try { - await SELF.fetch('https://example.com/gh/test/repo', { + // Malformed headers should be rejected before the request is dispatched. + expect(() => { + new Request('https://example.com/gh/test/repo', { headers: { 'X-Test': 'value\r\nX-Injected: malicious' } }); - // If it doesn't throw, it should not be a server error - } catch (error) { - // Expected to throw TypeError for invalid header value - expect(/** @type {Error} */ (error).message).toMatch(/[Ii]nvalid|[Hh]eader/); - } + }).toThrow(/[Ii]nvalid|[Hh]eader/); }); });