Skip to content

fix: guard shouldCompress against non-string Content-Type - #432

Open
gnotos wants to merge 1 commit into
fastify:mainfrom
gnotos:fix/non-string-content-type
Open

gnotos wants to merge 1 commit into
fastify:mainfrom
gnotos:fix/non-string-content-type

Conversation

@gnotos

@gnotos gnotos commented Sep 20, 2026

Copy link
Copy Markdown

Checklist

Follow-up to #331.

While investigating that issue I found that shouldCompress assumes type is always a string:

js
const data = mimedb[type.split(';', 1)[0].trim().toLowerCase()]

Any non-string value throws a TypeError there. Calling the function directly:

"application/force-download"   -> false
["application/force-download"] -> TypeError: type.split is not a function
123                            -> TypeError: type.split is not a function
undefined                      -> TypeError: Cannot read properties of undefined

To be clear about scope: I could not reproduce this through an actual HTTP request on current main. Fastify appears to drop an array Content-Type before the onSend hook runs, so a non-string value never reaches shouldCompress on that path. I've posted the details in #331 — the originally reported crash does not seem reproducible on v9.2.0.

This PR is therefore a defensive guard rather than a crash fix: a single early return that makes the function's contract explicit and its behaviour consistent for any non-string input. The test covers the array Content-Type path end to end.

Happy to close this if you'd rather not add a guard for an unreachable path.

@mcollina

Copy link
Copy Markdown
Member

Can you fix linting?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants