ppkarwasz opened a new issue, #4352:
URL: https://github.com/apache/logging-log4j2/issues/4352

   ## Description
   
   An HTTP appender header whose value contains a runtime lookup, such as
   
   ```xml
   <Http name="HTTP" url="https://example.com/logs";>
     <Property name="X-Tenant" value="$${ctx:tenant}"/>
     <JsonTemplateLayout/>
   </Http>
   ```
   
   is evaluated for every event in `HttpURLConnectionManager.send`
   and passed to `HttpURLConnection.setRequestProperty`.
   If the resolved value contains a CR or LF character, the JDK rejects it with 
an `IllegalArgumentException`,
   so the whole event is not sent (and is reported as an appender error).
   Context data such as `${ctx:...}` often comes from request headers,
   so a single value containing a line break is enough to lose the event.
   
   Expected behavior: a header value that cannot be sent should not cost the 
event.
   For example, the appender could strip or replace CR/LF characters in 
evaluated header values,
   or skip the offending header and report it through the status logger.
   
   ## Configuration
   
   **Version:** 2.26.1 (and `2.x` at `d631e82`)
   
   **Operating system:** any
   
   **JDK:** any
   
   ## Logs
   
   An `IllegalArgumentException` from 
`sun.net.www.protocol.http.HttpURLConnection.checkMessageHeader`
   ("Illegal character(s) in message header value"), wrapped in an appender 
error.
   
   ## Reproduction
   
   With the configuration above, run `ThreadContext.put("tenant", "a\nb")` and 
log an event: the event is not sent.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to