req' = updateAuthority host port req
in
setRequest req'
- -- HTTP/1.1 requests MUST have a Host header.
+ -- HTTP/1.1 requests MUST have a Host header, but if
+ -- the requested URI has an authority, the value of
+ -- Host header must be ignored. See:
+ -- http://tools.ietf.org/html/rfc2616#section-5.2
HttpVersion 1 1
→ case getHeader "Host" req of
Just str
- → let (host, port)
- = parseHost str
- req' = updateAuthority host port req
- in
- setRequest req'
+ | isNothing ∘ uriAuthority ∘ reqURI $ req
+ → let (host, port)
+ = parseHost str
+ req' = updateAuthority host port req
+ in
+ setRequest req'
+ | otherwise
+ → return ()
Nothing
→ setStatus BadRequest
-- Should never reach here...
(hText, pAscii)
updateAuthority ∷ CI Text → Ascii → Request → Request
-updateAuthority host port req
- = let uri = reqURI req
- uri' = uri {
+updateAuthority host port req@(Request {..})
+ = let uri' = reqURI {
uriAuthority = Just URIAuth {
uriUserInfo = ""
, uriRegName = cs $ CI.original host