Sönke Liebau created NIFI-16332:
-----------------------------------

             Summary: StandardUploadRequestReplicator treats forwarded headers 
case-sensitive, which can lead to duplicate headers making forwarded requests 
invalid
                 Key: NIFI-16332
                 URL: https://issues.apache.org/jira/browse/NIFI-16332
             Project: Apache NiFi
          Issue Type: Bug
          Components: Core Framework
    Affects Versions: 2.11.0, 2.10.0, 2.9.0
            Reporter: Sönke Liebau
            Assignee: Sönke Liebau


https://issues.apache.org/jira/browse/NIFI-15784 introduced copying of the 
headers from incoming requests into the requests that are forwarded to other 
cluster nodes.

It uses a 
[HashMap|https://github.com/apache/nifi/blob/b6a04999e8aea33a44dde95299cc04456567b66c/nifi-framework-bundle/nifi-framework/nifi-framework-cluster/src/main/java/org/apache/nifi/cluster/coordination/http/replication/StandardUploadRequestReplicator.java#L185-L190]
 for building the outgoing headers, with case-sensitive Strings as the keys, 
into which it first copies the headers from the incoming requests and then 
inserts a default `Content-Type` header: 
[source|https://github.com/apache/nifi/blob/b6a04999e8aea33a44dde95299cc04456567b66c/nifi-framework-bundle/nifi-framework/nifi-web/nifi-web-api/src/main/java/org/apache/nifi/web/api/ControllerResource.java#L2865-L2867]

If the incoming request had a content type header with different capitalization 
than 
[Content-Type|https://github.com/apache/nifi/blob/b6a04999e8aea33a44dde95299cc04456567b66c/nifi-framework-bundle/nifi-framework/nifi-web/nifi-web-api/src/main/java/org/apache/nifi/web/api/ControllerResource.java#L148-L149]
 this will lead to duplicate headers in the outgoing request. If the incoming 
request had

"content-type: application/octet-stream"

the replicated one will have: 
 
"content-type: application/octet-stream" and "Content-Type: 
application/octet-stream"
 
which gets rejected by the receiving NiFi node with a 400 response code.

This is influenced by the HTTP version that is used on the incoming request, 
http1.1 allows mixed case headers, so sending an http1.1 request with 
'Content-Type' will work, because they "collide" in the HashMap and only one 
header is forwarded, but sending an http2 request will error in all cases, as 
headers are normalized to lowercase there and a second headers will be inserted.

We could probably argue about the "correct" value for the forwarded requests, 
but at the very least, we should fix the duplication, so the upload works in 
all cases.

I would suggest always sending `content-type` as that is "the future" and 
mostly the nodes should agree on http2 for the cluster protocol, which means 
downstream components would normalize to that value anyway.

Happy to open a PR as basis for discussion.

 
 
 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to