fix: make configured resp CT lowercase - #3648
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe parser now lowercases configured MIME types before adding them to the response-body inspection set. A regression case checks mixed-case MIME types and expects HTTP 403 when the response body contains ChangesResponse MIME type matching
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Mixed-case configured MIME types now match normalized response headers, allowing response-body inspection to run as intended. The change is ready to merge; the regression test was not run as part of this review. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 2 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation consistently normalizes configuration values and includes focused regression coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Normalizes configured response MIME types so mixed-case values cannot bypass response-body inspection.
Changes:
- Lowercases
SecResponseBodyMimeTypevalues during parsing. - Updates generated parser output.
- Adds mixed-case regression coverage.
| File | Description |
|---|---|
src/parser/seclang-parser.yy |
Normalizes configured MIME types. |
src/parser/seclang-parser.cc |
Updates pregenerated parser code. |
test/test-cases/regression/variable-RESPONSE_BODY.json |
Tests mixed-case configuration. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|



what
Make configured
SecResponseBodyMimeTypetypes lowercase.why
Without this, if the admin puts the CT with not lowercase, the engine will skip the response body check.
references
Summary by CodeRabbit