Skip to content

Support raw BodyInit values in converted server requests - #6989

Merged
tim-smart merged 2 commits into
mainfrom
audit/repro-unstable-http-httpserverrequest-raw-body
Aug 4, 2026
Merged

Support raw BodyInit values in converted server requests#6989
tim-smart merged 2 commits into
mainfrom
audit/repro-unstable-http-httpserverrequest-raw-body

Conversation

@fubhy

@fubhy fubhy commented Aug 4, 2026

Copy link
Copy Markdown
Member

Summary

fromClientRequest preserves a raw string body, but reading it through the server request body accessors fails with HttpServerError(RequestParseError) instead of returning its bytes or text.

Important

This PR starts with focused failing reproduction tests. Add the implementation fix to this same branch; CI is expected to fail until that fix is included.

Client request conversion rejects ordinary raw BodyInit values

Module: HttpServerRequest
Audit ID: unstable-http-httpserverrequest-raw-body
Severity / confidence: medium / high

What happens

fromClientRequest preserves a raw string body, but reading it through the server request body accessors fails with HttpServerError(RequestParseError) instead of returning its bytes or text.

Why it happens

HttpBody.raw accepts runtime body values, and strings are valid Fetch BodyInit values, but rawBodyStream only supports Request, FormData, and ReadableStream, while rawBodyBytes only supports Blob and Request. A raw string therefore fails as an unsupported body type.

Expected behavior

fromClientRequest preserves a client's body and exposes it through the server request body accessors.

Relevant implementation

These links and excerpts are pinned to audit base c9b56ab507f224426ee8388dc450da447ec4715f.

View problematic code at packages/effect/src/unstable/http/HttpServerRequest.ts:733-782
  get stream(): Stream.Stream<Uint8Array, HttpServerError> {
    const body = this.source.body
    switch (body._tag) {
      case "Empty": {
        return Stream.empty
      }
      case "Uint8Array": {
        return Stream.succeed(body.body)
      }
      case "Stream": {
        return Stream.mapError(body.stream, (cause) => requestParseError(this, undefined, cause))
      }
      case "FormData": {
        return streamFromReadable(this, new Response(body.formData).body)
      }
      case "Raw": {
        return rawBodyStream(this, body.body)
      }
    }
  }

  private bytesEffect: Effect.Effect<Uint8Array, HttpServerError> | undefined
  private get bytes(): Effect.Effect<Uint8Array, HttpServerError> {
    if (this.bytesEffect) {
      return this.bytesEffect
    }
    const body = this.source.body
    let effect: Effect.Effect<Uint8Array, HttpServerError>
    switch (body._tag) {
      case "Empty": {
        effect = Effect.succeed(new Uint8Array(0))
        break
      }
      case "Uint8Array": {
        effect = Effect.succeed(body.body)
        break
      }
      case "FormData": {
        effect = bytesFromBodyInit(this, body.formData)
        break
      }
      case "Stream": {
        effect = Stream.mkUint8Array(this.stream)
        break
      }
      case "Raw": {
        effect = rawBodyBytes(this, body.body)
        break
      }
    }

View exact lines on GitHub

Excerpt truncated. Open the complete packages/effect/src/unstable/http/HttpServerRequest.ts:733-784 range.

View problematic code at packages/effect/src/unstable/http/HttpServerRequest.ts:862-886
const rawBodyStream = (request: HttpServerRequest, body: unknown): Stream.Stream<Uint8Array, HttpServerError> => {
  if (body instanceof Request) {
    return streamFromReadable(request, body.body)
  }
  if (isFormData(body)) {
    return streamFromReadable(request, new Response(body).body)
  }
  if (isReadableStream(body)) {
    return streamFromReadable(request, body)
  }
  return Stream.fail(requestParseError(request, "Unsupported body type"))
}

const rawBodyBytes = (request: HttpServerRequest, body: unknown): Effect.Effect<Uint8Array, HttpServerError> => {
  if (body instanceof Blob) {
    return bytesFromBodyInit(request, body)
  }
  if (body instanceof Request) {
    return Effect.tryPromise({
      try: () => body.arrayBuffer().then((buffer) => new Uint8Array(buffer)),
      catch: (cause) => requestParseError(request, undefined, cause)
    })
  }
  return Effect.fail(requestParseError(request, "Unsupported body type"))
}

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/unstable/http/HttpServerRequest.test.ts

Observed failure: Failed as intended with HttpServerError(RequestParseError): Unsupported body type.

Implementation handoff

The initial reproduction tests on this branch are the regression specification for the implementation fix that should follow in this PR.

  1. Start with the pinned implementation excerpts and the Why it happens analysis above.
  2. Change the implementation so it satisfies the stated Expected behavior; do not weaken or remove the reproduction assertions.
  3. Run the focused reproduction command(s) and confirm the observed failures become passing tests:
pnpm test --run packages/effect/test/unstable/http/HttpServerRequest.test.ts
  1. Run the affected package's existing tests, then the repository lint and type checks before requesting review.

Audit provenance

  • Audit base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Reproduction base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Findings: unstable-http-httpserverrequest-raw-body
  • Initial patch: focused reproduction tests; implementation fix pending

Closes EFF-426

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 4, 2026
@changeset-bot

changeset-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d52089e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node-shared Patch
@effect/platform-node Patch
@effect/vitest Patch
@effect/ai-anthropic Patch
@effect/ai-openai-compat Patch
@effect/ai-openai Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Aug 4, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

This PR currently adds only the regression test; the implementation fix is still pending. CI is expected to fail until rawBodyStream / rawBodyBytes are updated to handle raw string BodyInit values.

Reviewed changes — Added one test in packages/effect/test/unstable/http/HttpServerRequest.test.ts that verifies HttpServerRequest.fromClientRequest exposes a raw string body via .text.

  • Test is well-targeted and fails with the exact bug described (HttpServerError(RequestParseError): Unsupported body type).
  • The test uses it.effect and assert.strictEqual consistently with the surrounding suite.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | Fix all ➔Fix 👍s ➔View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

Comment thread packages/effect/test/unstable/http/HttpServerRequest.test.ts
@tim-smart
tim-smart enabled auto-merge (squash) August 4, 2026 22:52

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes — Since the prior Pullfrog review, the implementation fix landed on the branch.

  • Implemented raw BodyInit handling in packages/effect/src/unstable/http/HttpServerRequest.ts: rawBodyStream and rawBodyBytes now route standard BodyInit values through new Response(body) via a new isBodyInit predicate.
  • Expanded regression coverage in packages/effect/test/unstable/http/HttpServerRequest.test.ts to assert .text, .arrayBuffer, and .stream behavior for raw string and URLSearchParams bodies.
  • Added a patch changeset describing the fix.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@tim-smart
tim-smart merged commit 2e6f760 into main Aug 4, 2026
20 checks passed
@tim-smart
tim-smart deleted the audit/repro-unstable-http-httpserverrequest-raw-body branch August 4, 2026 23:14
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 7.06 KB 7.06 KB 0.00 KB (0.00%)
batching.ts 9.86 KB 9.86 KB 0.00 KB (0.00%)
brand.ts 6.34 KB 6.34 KB 0.00 KB (0.00%)
cache.ts 10.62 KB 10.71 KB -0.09 KB (-0.83%)
config.ts 20.60 KB 20.60 KB 0.00 KB (0.00%)
differ.ts 20.20 KB 20.20 KB 0.00 KB (0.00%)
http-client.ts 21.49 KB 21.58 KB -0.09 KB (-0.41%)
logger.ts 10.76 KB 10.84 KB -0.08 KB (-0.76%)
metric.ts 8.98 KB 8.98 KB 0.00 KB (0.00%)
optic.ts 7.18 KB 7.18 KB 0.00 KB (0.00%)
pubsub.ts 14.90 KB 14.99 KB -0.09 KB (-0.57%)
queue.ts 11.58 KB 11.66 KB -0.08 KB (-0.68%)
schedule.ts 10.74 KB 10.83 KB -0.09 KB (-0.80%)
schema-class.ts 19.14 KB 19.14 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.96 KB 28.96 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.29 KB 25.29 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.30 KB 13.38 KB -0.09 KB (-0.64%)
schema-string.ts 10.94 KB 10.94 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.17 KB 15.17 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.94 KB 21.94 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.34 KB 24.34 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.18 KB 19.18 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.87 KB 18.87 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.60 KB 22.60 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.52 KB 19.52 KB 0.00 KB (0.00%)
schema.ts 18.41 KB 18.41 KB 0.00 KB (0.00%)
stm.ts 12.54 KB 12.63 KB -0.09 KB (-0.74%)
stream.ts 9.80 KB 9.80 KB 0.00 KB (0.00%)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 audit Findings originating from the Effect runtime correctness audit bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants