fix(ws): enforce payload length encoding minimality and MSB constraints

Independently reported in parallel by DatanoiseTV <syso.berlin@icloud.com>
This commit is contained in:
Ashish Sharma
2026-07-07 17:46:23 +08:00
parent ebe89b6fb5
commit c4de8d52e7
4 changed files with 305 additions and 179 deletions
+2 -3
View File
@@ -60,9 +60,8 @@ menu "HTTP Server"
Sec-WebSocket-Key), rejects frames with reserved RSV bits, reserved or
fragmented control opcodes, non-minimal payload length encodings, and
frames whose 64-bit length has the MSB set; sends a CLOSE frame on
protocol errors; validates CLOSE frame status codes and UTF-8 reason;
validates UTF-8 text payloads; and blocks outbound data frames once a
CLOSE has been sent or received.
protocol errors; and blocks outbound data frames once a CLOSE has been
sent or received.
This option defaults to off in this release cycle so existing deployments
see no behavior change. Enable to opt into stricter enforcement; lenient