A delivery set Content-Type from the event's ContentType and then added the inbound Content-Type from the event's stored headers, so the target could receive two values. The inbound Content-Type is no longer forwarded from the stored headers; the receiver already saved it as the event's ContentType. Which value wins is now stated at applyRequestHeaders: a Content-Type configured on the target, otherwise the event's ContentType, otherwise none. Model: opus-5-5
This commit is contained in:
@@ -541,6 +541,11 @@ func isForwardableHeader(name string) bool {
|
||||
"Upgrade", "Proxy-Authorization",
|
||||
"Proxy-Connection", "Content-Length":
|
||||
return false
|
||||
case "Content-Type":
|
||||
// applyRequestHeaders sets Content-Type itself. The receiver
|
||||
// already stored this inbound value as the event's
|
||||
// ContentType, so forwarding it too would send it twice.
|
||||
return false
|
||||
default:
|
||||
return true
|
||||
}
|
||||
@@ -553,6 +558,10 @@ func isForwardableHeader(name string) bool {
|
||||
// policy strips exactly that set on a hop that leaves the origin,
|
||||
// so the forward set is decided here and only here — a header added
|
||||
// to it is covered off-origin without a second edit elsewhere.
|
||||
//
|
||||
// Content-Type goes out once: a Content-Type configured on the target
|
||||
// wins, otherwise the event's ContentType, otherwise none. The inbound
|
||||
// Content-Type in the event's headers is never forwarded.
|
||||
func applyRequestHeaders(
|
||||
req *http.Request,
|
||||
event *database.Event,
|
||||
@@ -573,10 +582,10 @@ func applyRequestHeaders(
|
||||
|
||||
req.Header.Set("User-Agent", "webhooker/1.0")
|
||||
|
||||
// Content-Type describes the body being sent rather than the
|
||||
// sender, and the delivery path sets it from the event itself.
|
||||
// A 307/308 preserves the body across hosts, so stripping it
|
||||
// would send that body untyped.
|
||||
// A Content-Type configured on the target describes the body
|
||||
// being sent rather than the sender. A 307/308 preserves the
|
||||
// body across hosts, so stripping it would send that body
|
||||
// untyped.
|
||||
delete(originScoped, "Content-Type")
|
||||
|
||||
// User-Agent is overwritten just above, so an inbound one never
|
||||
|
||||
Reference in New Issue
Block a user