Skip to content

Give a URL with no path the path / before sending it - #112

Merged
liquidsec merged 1 commit into
devfrom
fix-h2-empty-path
Oct 5, 2026
Merged

liquidsec merged 1 commit into
devfrom
fix-h2-empty-path

Conversation

@liquidsec

Copy link
Copy Markdown
Contributor

Fixes #111.

A URL with a query but no path, like https://crt.sh?q=example.com, went out over HTTP/2 with :path set to ?q=example.com, and servers reject that with a 400. The client now adds the / when it first reads the URL and when it follows a redirect, the same way curl and browsers do.

The new tests in tests/h2_path.rs run a small local HTTP/2 server that records the :path it gets, and cover both a direct request and a redirect. To build that server, the TLS test helper can now offer HTTP/2, and hyper's server feature is added as a test-only dependency.

A URL like https://crt.sh?q=example.com went out over HTTP/2 with :path
set to ?q=example.com, because hyper builds :path from the URI's
path-and-query as written. Servers answer that with a 400. The request
URL and redirect targets now get a leading / when they have a host but
no path, the same as curl and browsers.

Fixes #111
@liquidsec
liquidsec merged commit 6ae03fe into dev Oct 5, 2026
15 checks passed
@liquidsec
liquidsec deleted the fix-h2-empty-path branch October 5, 2026 20:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants