fix: use OR operator in includesCredentials per WHATWG URL Standard#4816
Merged
KhafraDev merged 1 commit intonodejs:mainfrom Feb 7, 2026
Merged
Conversation
The includesCredentials function used AND (&&) instead of OR (||), causing it to return false for URLs with only a username or only a password. Per WHATWG URL Standard §4.4, a URL includes credentials if its username OR its password is not the empty string. Fixes: nodejs#4815
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #4816 +/- ##
=======================================
Coverage 93.25% 93.25%
=======================================
Files 109 109
Lines 34153 34153
=======================================
Hits 31848 31848
Misses 2305 2305 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Merged
slagiewka
pushed a commit
to slagiewka/undici
that referenced
this pull request
Feb 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
includesCredentials()(lib/web/fetch/util.js):&&→||includesCredentials()covering all credential combinationsProblem
The
includesCredentials()function uses AND (&&) instead of OR (||), contradicting both:This causes the Authorization header to be silently omitted during authentication retries for URLs with only a username (e.g.,
http://apitoken@host) or only a password (e.g.,http://:secret@host).Fix
function includesCredentials (url) { // A URL includes credentials if its username or password is not the empty string. - return !!(url.username && url.password) + return !!(url.username || url.password) }Test plan
truetruetruefalseFixes: #4815
Ref: CWE-480: Use of Incorrect Operator