Skip to content

X-Deploy-App header carries the raw UTF-8 app name, so non-ASCII app names break HTTP clients #58

Description

@thorwhalen

An app whose directory name has a non-ASCII character (e.g. café) is discovered and served, but DeployHeadersMiddleware puts the name verbatim into the X-Deploy-App response header as UTF-8 bytes (b'caf\xc3\xa9'). HTTP header values are expected to be ASCII or latin-1: httpx (and so Starlette's TestClient) raises UnicodeEncodeError on such a response, and other clients may mangle it.

Found while testing analytics for #55. Repro: an app dir apps/café/frontend/index.html, build_backend(discover_apps(...)), GET /café/ → the http.response.start headers contain (b'x-deploy-app', b'caf\xc3\xa9').

Suggested fix: percent-encode the value (urllib.parse.quote(name, safe="")), as analytics does for its store keys. Or refuse non-ASCII app names at discovery with a clear error. Either way, add a test with a non-ASCII app name through the full stack.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions