Repository navigation
maxHeaderSize option on HTTPS server is not working #38954
Description
Activity
- changed the title
[-]add maxHeaderSize to HTTPS server not working[/-][+]maxHeaderSize option on HTTPS server is not working[/+]on Jun 7, 2021 - addedhttpsIssues and PRs related to the https subsystem.Issues and PRs related to the https subsystem.
on Jun 7, 2021 Linking for reference: nodejs/help#3401
Hi, @SantanM
Thanks for bug reporting,How do you generate headers for your request? If possible, could you provide a code snippet containing both server and request? It would be very helpful.
I've written a case with testing tools of Node.js, it passes on v12.19.0 (interestingly, fails on v14 and above, it seems maxHeaderSize is ignored (always 200)? but it may be different issue I guess...)
'use strict' const assert = require('assert'); const common = require('../common'); const https = require('https'); const fixtures = require('../common/fixtures'); const options = { key: fixtures.readKey('agent1-key.pem'), cert: fixtures.readKey('agent1-cert.pem') }; const maxHeaderSize = 8192 const body = 'hello world\n'; const serverCallback = function (req, res) { res.writeHead(200, { 'content-type': 'text/plain' }); res.end(body); }; // test header size is larger than maxHeaderSize { const server = https.createServer({ ...options, maxHeaderSize }, serverCallback) server.listen(0, common.mustCall(() => { const serverPort = server.address().port const reqOptions = { hostname: '127.0.0.1', port: serverPort, path: '/', method: 'GET', rejectUnauthorized: false, headers: { "h": 'a'.repeat(maxHeaderSize + 1) } }; const req = https.request(reqOptions, common.mustCall((res) => { assert.strictEqual(res.statusCode, 431) res.on('data', function (d) { }); res.on('end', common.mustCall(() => { server.close() })) })).end() })) } // test header size is in the range { const server = https.createServer({ ...options, maxHeaderSize }, serverCallback) server.listen(0, common.mustCall(() => { const serverPort = server.address().port const reqOptions = { hostname: '127.0.0.1', port: serverPort, path: '/', method: 'GET', rejectUnauthorized: false, headers: { // some other header overhead "h": 'a'.repeat(maxHeaderSize - 200) } }; const req = https.request(reqOptions, common.mustCall((res) => { assert.strictEqual(res.statusCode, 200) res.on('data', function (d) { }); res.on('end', common.mustCall(() => { server.close() })) })).end() })) }
Well, never mind,
maxHeaderSizeis unconfigurable forhttps.createServer, investigating further.Thanks for checking. Keep us updated on the next plan.
Being able to set
maxHeaderSizeon a server was added by #30570 but that was introduced in Node.js 13.3.0 and is not present in Node.js 12. There was a suggestion that it was "backportable to Node 12 with a bit of work" (#30570 (comment)) but that "bit of work" never happened and is unlikely to now that Node.js 12 is in maintenance and does not get new features.Reacted by bl-ueI think
maxHeaderSizehas never been implemented inhttpsServer. #30570 addedmaxHeaderSizeforhttp.Serverbut not forhttps. Therefore,https.createServer
options Accepts options from tls.createServer(), tls.createSecureContext() and http.createServer().The doc is wrong.
https.createServer([options][, requestListener])will not accept all options ofhttp.createServer(). At least,maxHeaderSizeis not supported.For now, I think the only way to control the maximun header size of a HTTPS Server is via CLI option
--max-http-header-size.Also, it seems fairly simple to bring
maxHeaderSizeintohttps.Server, I may open a PR in days.- added a commit that references this issue
on Jul 11, 2021 @Ayase-252 - The changes you made will be replicated to lower versions, more particularly to v14.XX? Could you confirm?
@SantanM I think it has been released in v16.5.0. It has not been backported to v14.x yet. Hopefully soon.
- added a commit that references this issue
on Sep 4, 2021 - added a commit that references this issue
on May 22, 2026
What steps will reproduce the bug?
Creating a server using HTTPS module with option
maxHeaderSize, like below. While increasingmaxHeaderSize, the server still shows 431 error for large header.How often does it reproduce? Is there a required condition?
It seems (according to the documentation) the options of HTTP server are applicable to HTTPS, but the value does not seem to work in my case (seeing 431 error always)
What is the expected behavior?
In doing so, I am expecting the large header sent to the server is accepted and does not return 431 error.
What do you see instead?
HTTP 431 error
Additional information
The test cases of
maxHeaderSizeoption are covered only for HTTP Server module and not HTTPS. I don't think it has been tested with HTTPS module.