Express returns a non-compliant HTTP/206 response when gzip is enabled
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- javascript, node.js
- Domain
- backend
Research direction
Start with the linked nodejs-express-range-headers reproduction and RFC7233, then trace how the compression middleware handles Range requests and produces response status and headers. Done means compressed responses no longer return incorrect HTTP/206 Content-Range values; verify the behavior with a focused regression test if the project provides one.
Written by the indexing model from the issue text.
Description
CDNs (mostly Azure Front Door) is using HTTP Range Requests to retrieve data from Origin when caching enabled.
Express should ignore Range: requests header when gzip compression is in place since Express is unable to respond a HTTP/206 compliant answer with the right computed Content-Range header in the response that is taking the compressed data length into account.
A fair compliant workaround is to, in that very case of compression where computing Content-Range values would be too complex, ignore client's Range: header in the request, and answer the whole compressed content in a HTTP/200 response.
Handling Range: headers is optional so answering a HTTP/200 is OK.
Answering a HTTP/206 with wrong Content-Range values is notOK.
Meanwhile another workaround is to disable compression and make CDN handle it, or disable CDN caching, however it would be fair to expect Express to return a compliant HTTP response in any case.
References:
Details and highlighting Express behavior:
https://github.com/DanielLarsenNZ/nodejs-express-range-headers
- Dominant language
- JavaScript
- Stars
- 2.8k
- Forks
- 257
- Avg merge
- 3d 15h
- Merged PRs (30d)
- 3
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from expressjs/compression
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 62/100
expressjs/compression#254 · 2 comments ·
-
Compression v2May be free again @UlisesGascon claimed this 505 days ago, and no pull request is open. Open
expressjs/compression#234 · 1 reaction · 2 assignees ·
-
awaiting more info bug
Difficulty 4/5 3-5 days Newbie friendliness 35/100
expressjs/compression#220 · 11 comments · 2 reactions ·
-
Support zstdOpenenhancement future
Difficulty 4/5 3-5 days Newbie friendliness 30/100
expressjs/compression#217 · 4 comments · 11 reactions ·
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 45/100
expressjs/compression#135 · 2 comments ·
All issues in expressjs/compression
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
type/bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
Edit: RTE News LogoOpencheck:failed logos:edit
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
iptv-org/database#36354 · 1 comment ·
Maintainers usually reply within 4 days
-
status:untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
midnightntwrk/midnight-wallet#791 ·
Maintainers usually reply within 1 day