return 400 for an unparseable body, and cover origin validation

bodyParser caught parse failures and did nothing — the throw was commented out
and `body` was never set, so handlers destructured undefined and the client got
a 500 for a malformed request. Throw BAD_REQUEST instead.

Also adds the regression tests for the Host suffix match fixed in 2ca850c.

Verified against a running server: malformed JSON now 400, valid credentials
path still 401, spoofed Host still 403.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
brunorezio
2026-07-25 23:30:20 +01:00
co-authored by Claude Opus 5
parent 1eb8cfd273
commit c13875cef8
2 changed files with 36 additions and 2 deletions
+4 -2
View File
@@ -24,8 +24,10 @@ export const bodyParser: () => MiddlewareHandler = () => async (ctx, next) => {
// No recognized content type, set empty body
ctx.set('body', {});
}
} catch (ex) {
// throw errors.BAD_REQUEST('Invalid request body');
} catch {
// Previously swallowed, which left `body` unset — handlers then destructured undefined and the
// client got a 500 for what is squarely a malformed request.
throw errors.BAD_REQUEST('Invalid request body');
}
return next();