Conversation
youennf
reviewed
Apr 30, 2026
Based on Andreu's work at https://github.com/andreubotella/multipart-form-data with mostly editorial changes and some corrections. WPT coverage at fetch/api/response/response-form-data.html
Parsing: * Look for CRLF -- boundary in the body loop rather than the bare boundary. As written a part whose value merely contained the boundary would remove more bytes than the body has. Gecko and WebKit have the same bug. * Allow transport padding after the close delimiter, per RFC 2046. This works in all three implementations. * Reject an empty boundary parameter, reachable through boundary="". * Do not reverse the %0A, %0D and %22 escapes. No implementation does, and as 0x25 (%) is not escaped they are ambiguous anyway. * Normalize a part's Content-Type the way the File constructor normalizes its type member, instead of only dropping non-ASCII values. * Leave parsing the Content-Disposition value undefined and marked XXX. The strict matching this had is stricter than every implementation, and this ought to share a Content-Disposition parser with downloads. Serializing: * Set up the stream with byte reading support, as Response's body is a byte stream for every other BodyInit. * Acquire the file reader once instead of on each pull, which would throw as the stream is already locked. * Take the chunk off the list before recursing into the pull algorithm. * Empty the chunks on cancelation so no further file is opened. * Compute the length before creating the stream, which consumes the chunks.
annevk
force-pushed
the
annevk/multipart/form-data
branch
from
September 9, 2026 15:56
4af534c to
7c13fd7
Compare
This reuses extract a MIME type for a part's Content-Type. A header's value is now a byte sequence, as a part's can contain 0x00 (NUL).
annevk
marked this pull request as ready for review
September 11, 2026 15:54
zcorpan
reviewed
Sep 25, 2026
2 of 6 tasks
Member
|
AI re-review at df46626:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Based on Andreu's work at https://github.com/andreubotella/multipart-form-data with mostly editorial changes and some corrections.
This defines a multipart/form-data serializer, which HTML's form submission will use as well, and a parser for formData(), replacing the rough approximation that was there before. In particular:
Tests: web-platform-tests/wpt#59216
HTML PR: whatwg/html#12992
Fixes whatwg/html#6424 and fixes whatwg/html#7413.
(See WHATWG Working Mode: Changes for more details.)
Preview | Diff