Skip to content

Strip sec-ch-* client-hint headers by prefix for CORS classification - #48

Merged
mandatoryprogrammer merged 2 commits into
mandatoryprogrammer:mainfrom
m4dni5:pr-secch
Oct 5, 2026
Merged

mandatoryprogrammer merged 2 commits into
mandatoryprogrammer:mainfrom
m4dni5:pr-secch

Conversation

@m4dni5

@m4dni5 m4dni5 commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Chromium sends client-hint headers like sec-ch-ua-wow64 that aren't in ALWAYS_CLEAN_HEADERS. Requests carrying them return a 500 and their subresources fail to load.

Root cause

To classify a request, is_simple_cors_request requires every header to be on a fixed allowlist. Any header it doesn't recognize fails the check, no routing rule matches, and the request 500s.

New sec-ch-* headers appear with every Chrome release, so listing them one by one in ALWAYS_CLEAN_HEADERS breaks again each time.

Fix

Strip the whole sec-ch-* family by prefix before classification, so any current or future client hint is handled. Existing entries are left for any other consumers of the list.

Verification

Requests carrying sec-ch-ua-wow64: ?0 500'd before, route correctly after.

The client-hint header family is open-ended and grows with every Chrome
release (sec-ch-ua-wow64, sec-ch-ua-form-factors, ...). Enumerating them
in ALWAYS_CLEAN_HEADERS rots: any unlisted client-hint fails the
CORS-simple check and returns a 500 for that subresource request. Match
the whole sec-ch- family by prefix instead.
@m4dni5
m4dni5 marked this pull request as ready for review September 9, 2026 23:40
@mandatoryprogrammer mandatoryprogrammer changed the title Strip sec-ch-* client-hint headers by prefix for CORS classification Ignore client hints when classifying requests Oct 5, 2026
@mandatoryprogrammer mandatoryprogrammer changed the title Ignore client hints when classifying requests Strip sec-ch-* client-hint headers by prefix for CORS classification Oct 5, 2026
@mandatoryprogrammer

Copy link
Copy Markdown
Owner

Looks like unrelated concurrency cap code was in the PR, I removed it and reduced it to just the header strip logic. Thanks for the contribution!

@mandatoryprogrammer
mandatoryprogrammer merged commit 3b1d5e1 into mandatoryprogrammer:main Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants