Commit Graph
8 Commits
Author SHA1 Message Date
Mahavir Jain 442cc028b5 Merge branch 'fix/fix_esp_http_client_cross_origin_credentials' into 'master'
fix(esp_http_client): strip Authorization header on cross-origin redirect

Closes SEC-228 and SEC-049

See merge request espressif/esp-idf!48820
2026-07-06 12:20:51 +05:30
Ashish SharmaandClaude Opus 4.8 8c181842f1 feat(esp_http_client): detect oversized headers in tx buffer while sending request
When CONFIG_ESP_HTTP_CLIENT_STRICT_HEADER_BUFFER is enabled,
esp_http_client_request_send() fails fast when a single request header is
larger than buffer_size_tx, instead of silently emitting a truncated request.

The condition is reported with a dedicated ESP_ERR_HTTP_HEADER_TOO_LONG error
code rather than overloading ESP_ERR_HTTP_WRITE_DATA, so callers can tell a
permanent header-sizing failure apart from a transient write error. errno is
cleared on this path so the async caller (which maps errno == EAGAIN to "retry
later") does not spin retrying a request that can never succeed.

Closes https://github.com/espressif/esp-idf/issues/18639

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-25 18:24:42 +08:00
Ashish Sharma a4b10f1691 fix(esp_http_client): clear URL credentials and digest auth state on host change 2026-05-22 15:16:12 +08:00
Ashish Sharma 3ba6f4b786 fix(esp_http_client): strip Authorization header on cross-origin redirect 2026-05-22 15:08:14 +08:00
nilesh.kale 7edb4fae49 feat(esp_http_client): avoid dispatching of spurious event while closing closes connection
This commit updated the client closing condition to avoid spurious
dispatching of event HTTP_EVENT_DISCONNECTED while closing closeed connection.

Closes https://github.com/espressif/esp-idf/issues/16070
2025-08-12 17:31:50 +05:30
nilesh.kale 9c4c366d61 fix(esp_http_client): Added test case to verify set header functionality
This commit added testcase to verify esp_http_client_set_header
allows header value as NULL. Setting this NULL will delete the header.

Closes https://github.com/espressif/esp-idf/issues/15714
2025-04-04 21:00:45 +05:30
nilesh.kale 92027a9039 fix(esp_http_client): updated API esp_http_client_get_url to get URL in correct format
This commit updates the API to include the port number in the URL,
which was previously missing.
2024-12-18 12:00:55 +05:30
Harshit Malpani 791d17ac7f ci: Migrate unit-test for esp_http_client to component-test-apps 2022-08-22 16:57:32 +05:30