fix: skip request body for GET and HEAD requests#6350
Open
zongmingzhi wants to merge 13 commits into
Open
Conversation
GET and HEAD requests should not forward a request body through the HTTP client plugins. Sending a body can cause Reactor Netty or WebClient to emit unexpected transfer encoding headers, which may break compatibility with upstream servers. Add shared request-body eligibility logic in AbstractHttpClientPlugin and reuse it from both NettyHttpClientPlugin and WebClientPlugin.
Contributor
There was a problem hiding this comment.
Pull request overview
This PR aims to prevent the HTTP client plugins from forwarding request bodies for GET and HEAD requests, avoiding unexpected transfer-encoding behavior (e.g., Transfer-Encoding: chunked) that can break compatibility with some upstream servers.
Changes:
- Introduces shared request-body eligibility logic in
AbstractHttpClientPlugin. - Updates
WebClientPluginto only attach a request body for non-GET/HEAD methods. - Updates
NettyHttpClientPluginto skip sending a request body for GET/HEAD methods.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| shenyu-plugin/shenyu-plugin-httpclient/src/main/java/org/apache/shenyu/plugin/httpclient/AbstractHttpClientPlugin.java | Adds shared helper to decide whether request body should be forwarded. |
| shenyu-plugin/shenyu-plugin-httpclient/src/main/java/org/apache/shenyu/plugin/httpclient/WebClientPlugin.java | Uses shared helper to avoid attaching a body for GET/HEAD requests. |
| shenyu-plugin/shenyu-plugin-httpclient/src/main/java/org/apache/shenyu/plugin/httpclient/NettyHttpClientPlugin.java | Uses shared helper to avoid sending a body for GET/HEAD requests (Reactor Netty). |
Comments suppressed due to low confidence (1)
shenyu-plugin/shenyu-plugin-httpclient/src/main/java/org/apache/shenyu/plugin/httpclient/WebClientPlugin.java:69
- When skipping the request body for GET/HEAD, the code still forwards body-related headers from the incoming request (e.g., Content-Length / Transfer-Encoding / Content-Type / Expect). This can produce an invalid request (headers imply a body that is not sent) and may still trigger upstream compatibility issues.
.headers(headers -> {
headers.addAll(exchange.getRequest().getHeaders());
headers.remove(HttpHeaders.HOST);
Boolean preserveHost = exchange.getAttributeOrDefault(Constants.PRESERVE_HOST, Boolean.FALSE);
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+120
to
+122
| protected boolean isRequestBodyRequired(final String httpMethod) { | ||
| return !"GET".equals(httpMethod) && !"HEAD".equals(httpMethod); | ||
| } |
Comment on lines
78
to
+82
| }).request(HttpMethod.valueOf(httpMethod)).uri(uri.toASCIIString()) | ||
| .send((req, nettyOutbound) -> nettyOutbound.send(body.map(dataBuffer -> ((NettyDataBuffer) dataBuffer).getNativeBuffer()))) | ||
| .send((req, nettyOutbound) -> { | ||
| // Do not send a request body for GET/HEAD. Otherwise Reactor Netty may add | ||
| // Transfer-Encoding: chunked and cause compatibility issues with some upstream servers. | ||
| if (isRequestBodyRequired(httpMethod)) { |
Comment on lines
+120
to
+122
| protected boolean isRequestBodyRequired(final String httpMethod) { | ||
| return !"GET".equals(httpMethod) && !"HEAD".equals(httpMethod); | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR prevents the HTTP client plugins from forwarding request bodies for GET and HEAD requests.
Sending a body for GET or HEAD may cause Reactor Netty or WebClient to emit unexpected transfer encoding headers, which can break compatibility with some upstream servers.
Changes
AbstractHttpClientPlugin.NettyHttpClientPlugin.WebClientPlugin.Tests
./mvnw -pl shenyu-plugin/shenyu-plugin-httpclient -am -DskipTests validate./mvnw -pl shenyu-plugin/shenyu-plugin-httpclient -am testChecklist
./mvnw -pl shenyu-plugin/shenyu-plugin-httpclient -am test.