Skip to content

Accept case-insensitive URI schemes in parse_url - #2609

Closed
xop01 wants to merge 1 commit into
yhirose:masterfrom
xop01:fix-scheme-case
Closed

xop01 wants to merge 1 commit into
yhirose:masterfrom
xop01:fix-scheme-case

Conversation

@xop01

@xop01 xop01 commented Oct 3, 2026

Copy link
Copy Markdown

Summary

  • parse_url accepted a scheme only when every character was already in a-z. RFC 3986 section 3.1 says the scheme is case-insensitive, so HTTP:// and Https:// are the same schemes as http:// and https://.
  • set_follow_location(true) therefore refused a valid Location, returned a null response, and reported Error::Unknown because the redirect failed without setting error.
  • The scheme is now stored in lowercase. h2:// and other non-alpha schemes are still rejected. Client and WebSocket constructors that compare against https / wss pick up HTTPS:// and WSS:// through the same parser.

Test plan

  • parse_url("HTTP://example.com/path") yields scheme http, and h2:// is still rejected
  • Local client/server: Location: HTTP://127.0.0.1:<port>/b is followed and returns 200
  • ParseUrlTest.VariousPatterns
  • RedirectLocationTest.FollowsUppercaseScheme

RFC 3986 treats the scheme as case-insensitive. "HTTP://" was rejected, so follow_location failed the whole Result with Error::Unknown and never requested the target.

Co-authored-by: Cursor <cursoragent@cursor.com>
@yhirose

yhirose commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Thanks for the PR. Rejecting an uppercase scheme in parse_url is deliberate and pinned by an existing test. I'd rather not loosen it without a concrete report from a real server. Closing.

@yhirose yhirose closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants