diff --git a/src/libraries/System.Net.HttpListener/src/System/Net/Managed/HttpListenerRequest.Managed.cs b/src/libraries/System.Net.HttpListener/src/System/Net/Managed/HttpListenerRequest.Managed.cs index 098782eec22151..840b0d8fc6205e 100644 --- a/src/libraries/System.Net.HttpListener/src/System/Net/Managed/HttpListenerRequest.Managed.cs +++ b/src/libraries/System.Net.HttpListener/src/System/Net/Managed/HttpListenerRequest.Managed.cs @@ -208,15 +208,15 @@ internal void FinishInitialization() internal void AddHeader(string header) { int colon = header.IndexOf(':'); - if (colon == -1 || colon == 0) + if (colon <= 0) { _context.ErrorMessage = HttpStatusDescription.Get(400); _context.ErrorStatus = 400; return; } - string name = header.AsSpan(0, colon).Trim().ToString(); - string val = header.AsSpan(colon + 1).Trim().ToString(); + string name = header.AsSpan(0, colon).ToString(); + string val = header.AsSpan(colon + 1).Trim(" \t").ToString(); if (name.Equals("content-length", StringComparison.OrdinalIgnoreCase)) { // To match Windows behavior: diff --git a/src/libraries/System.Net.HttpListener/tests/InvalidClientRequestTests.cs b/src/libraries/System.Net.HttpListener/tests/InvalidClientRequestTests.cs index 67e7c187225fba..00c52e667a1fb9 100644 --- a/src/libraries/System.Net.HttpListener/tests/InvalidClientRequestTests.cs +++ b/src/libraries/System.Net.HttpListener/tests/InvalidClientRequestTests.cs @@ -84,6 +84,13 @@ public static IEnumerable InvalidRequest_TestData() yield return new object[] { "GET {path} HTTP/1.1", null, new string[] { ":" }, null, "Bad Request" }; yield return new object[] { "GET {path} HTTP/1.1", null, new string[] { "\0:value" }, null, "Bad Request" }; yield return new object[] { "GET {path} HTTP/1.1", null, new string[] { "value:\0" }, null, "Bad Request" }; + if (Helpers.IsManagedImplementation) + { + yield return new object[] { "GET {path} HTTP/1.1", null, new string[] { " Header: value" }, null, "Bad Request" }; + yield return new object[] { "GET {path} HTTP/1.1", null, new string[] { "\tHeader: value" }, null, "Bad Request" }; + yield return new object[] { "GET {path} HTTP/1.1", null, new string[] { "Header : value" }, null, "Bad Request" }; + yield return new object[] { "GET {path} HTTP/1.1", null, new string[] { "Header\t: value" }, null, "Bad Request" }; + } yield return new object[] { "GET {path} HTTP/1.1", "", null, null, "Bad Request" }; yield return new object[] { "GET {path} HTTP/1.1", "Host: \r\n", null, null, "Bad Request" };