The GitHub Actions job "Groovy Snapshot Canary Build" on 
grails-core.git/feat/default-security-headers has failed.
Run started by GitHub user jdaugherty (triggered by jdaugherty).

Head commit for run:
8da7b05c58fd3ef2cca4509c7d7938dc48b6332d / James Daugherty 
<[email protected]>
Count writer output in encoded bytes, resolve the HSTS scheme without the 
request URL

The response wrapper compared writer output, counted in characters, against
the container's buffer and Content-Length, which are both in bytes. Three-byte
UTF-8 text therefore filled and committed an enlarged buffer before the
callback fired, and the headers were dropped. Tomcat keeps an enlarged buffer
on the recycled processor, so later requests were affected even on new
connections. Writer output is now counted as its encoded length: exactly for
UTF-8 and single-byte encodings, and at the encoding's maximum bytes per
character otherwise.

HSTS resolved the forwarded scheme through ServletServerHttpRequest.getURI(),
which throws for request paths that java.net.URI rejects but Tomcat accepts
through relaxedPathChars, turning those requests into 500s. The forwarded
headers are now applied to the request's scheme alone.

The upgrade note moves to its own section, the explicit-configuration wording
in the security guide matches the behavior, and the docs no longer place the
Grails character-encoding filter outside the security headers filter.
REVERSE_PROXY_REQUEST_HEADERS is no longer public API. The Tomcat spec checks
every default header value, covers multi-byte writer output, and uses @TempDir.

Report URL: https://github.com/apache/grails-core/actions/runs/36015566146

With regards,
GitHub Actions via GitBox

Reply via email to