Skip to content

fix: encode native multipart names and line breaks correctly - #225

Open
OskarEichler wants to merge 1 commit into
margelo:mainfrom
OskarEichler:codex/nitro-multipart-parameter-encoding
Open

fix: encode native multipart names and line breaks correctly#225
OskarEichler wants to merge 1 commit into
margelo:mainfrom
OskarEichler:codex/nitro-multipart-parameter-encoding

Conversation

@OskarEichler

@OskarEichler OskarEichler commented Aug 27, 2026

Copy link
Copy Markdown

Fixes

  • Escape quotes/CR/LF in native multipart field names and filenames.
  • Normalize field-name and string-value line endings to CRLF without modifying file bytes.
  • Reject file MIME types containing CR/LF before uploading malformed multipart headers.
  • Preserve field order, duplicate fields, Unicode, literal percent/backslash values, empty filenames and file metadata defaults.

Compatibility / breaking changes

Names and text values containing line breaks now use browser-compatible multipart encoding; quotes in parameters become percent-encoded. Invalid multiline MIME types now reject. File bytes, public signatures, buffer strategy and dependency versions are unchanged. This does not implement streaming uploads or bound upload memory.

Verification

24 external native serialization checks pass, executing the actual Swift/Kotlin serializers and comparing bytes with Node FormData (except retaining the existing explicit empty filename, which Node omits). 12 assertions fail on the original source. Both native examples build with tracing enabled; no physical device/network upload claim. No test/spec files changed.

Algorithm reference: HTML multipart encoding.

Fixes #224.

Consumer follow-up verification

The combined fixes are backported to an immutable 1.6.1 artifact. Both consuming app Android Debug variants, both iOS Debug Simulator variants, four production Metro bundles, 13 web targets, four browser-extension builds, lint and immutable installation pass. All 274 installed non-metadata files match the artifact. This is build verification, not a physical-device authentication/upload certification.

@vercel

vercel Bot commented Aug 27, 2026

Copy link
Copy Markdown

@OskarEichler is attempting to deploy a commit to the Margelo Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Multipart serializers corrupt names and filenames containing quotes or line breaks

1 participant