• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

elixir-mint / mint / 6588c77fc8f03adc9614e1e74dc270bce163d60e
91%

Build:
DEFAULT BRANCH: main
Ran 27 Sep 2026 01:29PM UTC
Jobs 1
Files 22
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

27 Sep 2026 01:28PM UTC coverage: 89.403% (+0.5%) from 88.92%
6588c77fc8f03adc9614e1e74dc270bce163d60e

push

github

web-flow
Validate and normalize HTTP/1 status lines and header fields (#513)

* Trim only SP and HTAB from Content-Length values

String.trim_trailing/1 also strips Unicode whitespace, so values such as
"5" followed by VT, FF, NBSP, NEL or U+3000 were accepted. RFC 9110
section 8.6 allows only digits, with optional whitespace around the field
value.

* Unfold obsolete line folding in HTTP/1 header values

Folded header and trailer values were delivered with the CRLF and leading
whitespace intact. RFC 9112 section 5.2 requires user agents to replace
each obs-fold with a space before interpreting the value. With
:stream_headers a header is emitted before its continuation line can be
seen, so folds are rejected with :invalid_header in that mode.

* Validate HTTP/1 status line version, status code and reason phrase

:erlang.decode_packet/3 accepts any major version, status codes with two or
four digits, and reason phrases containing control bytes. Only HTTP/1.x
with a single-digit minor version, three-digit status codes, and reason
phrases made of HTAB, SP, VCHAR and obs-text are accepted.

* Reject HTTP/1 header values containing control characters

Values with CR, NUL, DEL or other control bytes were delivered verbatim
in headers and trailers. RFC 9110 5.5 allows only HTAB, SP, VCHAR and
obs-text in a field value and requires recipients to reject or replace
CR, LF and NUL. The response now fails with :invalid_header or
:invalid_trailer_header, the same check the request encoder applies to
outgoing values.

* Reject HTTP/1 header and trailer lines with an empty field name

:erlang.decode_packet/3 accepts a line such as ": bar" and returns an
empty name, which was delivered to callers as {"", "bar"}. RFC 9110 5.1
defines field-name as a token of at least one character.

* Trim trailing whitespace from HTTP/1 header values

RFC 9112 5.1 excludes optional whitespace after a field value from the
value itself. :erlang.decode_packet/3 strips the leading whitespace but
... (continued)

82 of 85 new or added lines in 3 files covered. (96.47%)

1662 of 1859 relevant lines covered (89.4%)

648.52 hits per line

Uncovered Changes

Lines Coverage ∆ File
3
96.05
19.13% lib/mint/http1/response.ex
Jobs
ID Job ID Ran Files Coverage
1 6588c77fc8f03adc9614e1e74dc270bce163d60e.1 27 Sep 2026 01:29PM UTC 22
89.4
GitHub Action Run
Source Files on build 6588c77fc8f03adc9614e1e74dc270bce163d60e
  • Tree
  • List 22
  • Changed 3
  • Source Changed 0
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 6588c77f on github
  • Prev Build on main (#E2BD569B...)
  • Next Build on main (#F5FCED56...)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc