fix(ws): reject RSV bits, reserved opcodes, fragmented control frames

This commit is contained in:
Ashish Sharma
2026-07-07 17:43:16 +08:00
parent fbe6d9005a
commit ebe89b6fb5
3 changed files with 304 additions and 7 deletions
@@ -1786,12 +1786,16 @@ esp_err_t httpd_queue_work(httpd_handle_t handle, httpd_work_fn_t work, void *ar
* @note Please refer to RFC6455 Section 5.4 for more details
*/
typedef enum {
HTTPD_WS_TYPE_CONTINUE = 0x0,
HTTPD_WS_TYPE_TEXT = 0x1,
HTTPD_WS_TYPE_BINARY = 0x2,
HTTPD_WS_TYPE_CLOSE = 0x8,
HTTPD_WS_TYPE_PING = 0x9,
HTTPD_WS_TYPE_PONG = 0xA
HTTPD_WS_TYPE_CONTINUE = 0x0,
HTTPD_WS_TYPE_TEXT = 0x1,
HTTPD_WS_TYPE_BINARY = 0x2,
HTTPD_WS_TYPE_NON_CTRL_RES = 0x3, /*!< Reserved non-control opcode range start */
HTTPD_WS_TYPE_NON_CTRL_RES_END = 0x7, /*!< Reserved non-control opcode range end */
HTTPD_WS_TYPE_CLOSE = 0x8,
HTTPD_WS_TYPE_PING = 0x9,
HTTPD_WS_TYPE_PONG = 0xA,
HTTPD_WS_TYPE_CTRL_RES = 0xB, /*!< Reserved control opcode range start */
HTTPD_WS_TYPE_CTRL_RES_END = 0xF, /*!< Reserved control opcode range end */
} httpd_ws_type_t;
/**