cache.js 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676
  1. 'use strict'
  2. const {
  3. safeHTTPMethods,
  4. pathHasQueryOrFragment,
  5. hasSafeIterator,
  6. isValidHTTPToken
  7. } = require('../core/util')
  8. const { serializePathWithQuery } = require('../core/util')
  9. const MAX_DELTA_SECONDS = 2147483647
  10. const RESTRICTIVE_DIRECTIVE_NAMES = ['no-store', 'private', 'no-cache']
  11. const kInvalidCacheControlDirectives = Symbol('invalid cache-control directives')
  12. function trimOWS (value) {
  13. return value.replace(/^[\t ]+|[\t ]+$/g, '')
  14. }
  15. function arrayIncludes (array, value) {
  16. for (let i = 0; i < array.length; i++) {
  17. if (array[i] === value) {
  18. return true
  19. }
  20. }
  21. return false
  22. }
  23. function trimOWSStart (value) {
  24. return value.replace(/^[\t ]+/, '')
  25. }
  26. function trimOWSEnd (value) {
  27. return value.replace(/[\t ]+$/, '')
  28. }
  29. function findUnescapedQuote (value, start) {
  30. let escaped = false
  31. for (let i = start; i < value.length; i++) {
  32. if (escaped) {
  33. escaped = false
  34. } else if (value[i] === '\\') {
  35. escaped = true
  36. } else if (value[i] === '"') {
  37. return i
  38. }
  39. }
  40. return -1
  41. }
  42. function splitCacheControlHeaderValue (value) {
  43. const directives = []
  44. let start = 0
  45. let quoteStart = -1
  46. let inQuote = false
  47. let escaped = false
  48. for (let i = 0; i < value.length; i++) {
  49. if (inQuote) {
  50. if (escaped) {
  51. escaped = false
  52. } else if (value[i] === '\\') {
  53. escaped = true
  54. } else if (value[i] === '"') {
  55. inQuote = false
  56. quoteStart = -1
  57. }
  58. } else if (value[i] === '"') {
  59. inQuote = true
  60. quoteStart = i
  61. } else if (value[i] === ',') {
  62. directives.push({ value: value.substring(start, i), fromMalformedQuote: false })
  63. start = i + 1
  64. }
  65. }
  66. if (!inQuote) {
  67. directives.push({ value: value.substring(start), fromMalformedQuote: false })
  68. return directives
  69. }
  70. const tail = value.substring(start)
  71. const quoteOffset = quoteStart - start
  72. let tailStart = 0
  73. for (let i = 0; i < tail.length; i++) {
  74. if (tail[i] === ',') {
  75. directives.push({
  76. value: tail.substring(tailStart, i),
  77. fromMalformedQuote: tailStart > quoteOffset
  78. })
  79. tailStart = i + 1
  80. }
  81. }
  82. directives.push({
  83. value: tail.substring(tailStart),
  84. fromMalformedQuote: tailStart > quoteOffset
  85. })
  86. return directives
  87. }
  88. function markInvalidCacheControlDirective (directives, key) {
  89. let invalidDirectives = directives[kInvalidCacheControlDirectives]
  90. if (invalidDirectives === undefined) {
  91. invalidDirectives = new Set()
  92. Object.defineProperty(directives, kInvalidCacheControlDirectives, {
  93. value: invalidDirectives
  94. })
  95. }
  96. invalidDirectives.add(key)
  97. }
  98. function hasInvalidCacheControlDirective (directives, key) {
  99. return directives[kInvalidCacheControlDirectives]?.has(key) === true
  100. }
  101. function getMalformedRestrictiveDirectiveName (key) {
  102. for (const directiveName of RESTRICTIVE_DIRECTIVE_NAMES) {
  103. if (
  104. key.startsWith(directiveName) &&
  105. key.length > directiveName.length &&
  106. !isValidHTTPToken(key[directiveName.length])
  107. ) {
  108. return directiveName
  109. }
  110. }
  111. let tokenOnlyKey = ''
  112. let hasInvalidTokenChar = false
  113. for (let i = 0; i < key.length; i++) {
  114. if (isValidHTTPToken(key[i])) {
  115. tokenOnlyKey += key[i]
  116. } else {
  117. hasInvalidTokenChar = true
  118. }
  119. }
  120. if (hasInvalidTokenChar && arrayIncludes(RESTRICTIVE_DIRECTIVE_NAMES, tokenOnlyKey)) {
  121. return tokenOnlyKey
  122. }
  123. }
  124. /**
  125. * @param {import('../../types/dispatcher.d.ts').default.DispatchOptions} opts
  126. */
  127. function makeCacheKey (opts) {
  128. if (!opts.origin) {
  129. throw new Error('opts.origin is undefined')
  130. }
  131. let fullPath = opts.path || '/'
  132. if (opts.query && !pathHasQueryOrFragment(fullPath)) {
  133. fullPath = serializePathWithQuery(fullPath, opts.query)
  134. }
  135. return {
  136. origin: opts.origin.toString(),
  137. method: opts.method,
  138. path: fullPath,
  139. headers: opts.headers
  140. }
  141. }
  142. function appendHeader (headers, key, val) {
  143. const headerName = key.toLowerCase()
  144. const current = headers[headerName]
  145. const values = Array.isArray(val) ? val : [val]
  146. if (current === undefined) {
  147. headers[headerName] = Array.isArray(val) ? val.slice() : val
  148. } else if (Array.isArray(current)) {
  149. current.push(...values)
  150. } else {
  151. headers[headerName] = [current, ...values]
  152. }
  153. }
  154. /**
  155. * @param {Record<string, string[] | string>}
  156. * @returns {Record<string, string[] | string>}
  157. */
  158. function normalizeHeaders (opts) {
  159. let headers
  160. if (opts.headers == null) {
  161. headers = {}
  162. } else if (typeof opts.headers === 'object') {
  163. headers = {}
  164. if (hasSafeIterator(opts.headers)) {
  165. for (const x of opts.headers) {
  166. if (!Array.isArray(x)) {
  167. throw new Error('opts.headers is not a valid header map')
  168. }
  169. const [key, val] = x
  170. if (typeof key !== 'string' || typeof val !== 'string') {
  171. throw new Error('opts.headers is not a valid header map')
  172. }
  173. appendHeader(headers, key, val)
  174. }
  175. } else {
  176. for (const key of Object.keys(opts.headers)) {
  177. appendHeader(headers, key, opts.headers[key])
  178. }
  179. }
  180. } else {
  181. throw new Error('opts.headers is not an object')
  182. }
  183. return headers
  184. }
  185. /**
  186. * @param {any} key
  187. */
  188. function assertCacheKey (key) {
  189. if (typeof key !== 'object') {
  190. throw new TypeError(`expected key to be object, got ${typeof key}`)
  191. }
  192. for (const property of ['origin', 'method', 'path']) {
  193. if (typeof key[property] !== 'string') {
  194. throw new TypeError(`expected key.${property} to be string, got ${typeof key[property]}`)
  195. }
  196. }
  197. if (key.headers !== undefined && typeof key.headers !== 'object') {
  198. throw new TypeError(`expected headers to be object, got ${typeof key}`)
  199. }
  200. }
  201. /**
  202. * @param {any} value
  203. */
  204. function assertCacheValue (value) {
  205. if (typeof value !== 'object') {
  206. throw new TypeError(`expected value to be object, got ${typeof value}`)
  207. }
  208. for (const property of ['statusCode', 'cachedAt', 'staleAt', 'deleteAt']) {
  209. if (typeof value[property] !== 'number') {
  210. throw new TypeError(`expected value.${property} to be number, got ${typeof value[property]}`)
  211. }
  212. }
  213. if (typeof value.statusMessage !== 'string') {
  214. throw new TypeError(`expected value.statusMessage to be string, got ${typeof value.statusMessage}`)
  215. }
  216. if (value.headers != null && typeof value.headers !== 'object') {
  217. throw new TypeError(`expected value.rawHeaders to be object, got ${typeof value.headers}`)
  218. }
  219. if (value.vary !== undefined && typeof value.vary !== 'object') {
  220. throw new TypeError(`expected value.vary to be object, got ${typeof value.vary}`)
  221. }
  222. if (value.etag !== undefined && typeof value.etag !== 'string') {
  223. throw new TypeError(`expected value.etag to be string, got ${typeof value.etag}`)
  224. }
  225. }
  226. /**
  227. * @see https://www.rfc-editor.org/rfc/rfc9111.html#name-cache-control
  228. * @see https://www.iana.org/assignments/http-cache-directives/http-cache-directives.xhtml
  229. * @param {string | string[]} header
  230. * @returns {import('../../types/cache-interceptor.d.ts').default.CacheControlDirectives}
  231. */
  232. function parseCacheControlHeader (header) {
  233. /**
  234. * @type {import('../../types/cache-interceptor.d.ts').default.CacheControlDirectives}
  235. */
  236. const output = {}
  237. const invalidNumericDirectives = new Set()
  238. const invalidNoArgumentDirectives = new Set()
  239. const directives = splitCacheControlHeaderValue(Array.isArray(header) ? header.join(',') : header)
  240. for (let i = 0; i < directives.length; i++) {
  241. const directiveRecord = directives[i]
  242. const directive = directiveRecord.value.toLowerCase()
  243. const fromMalformedQuote = directiveRecord.fromMalformedQuote
  244. const keyValueDelimiter = directive.indexOf('=')
  245. let key
  246. let value
  247. let keyHasTrailingWhitespace = false
  248. let valueHasLeadingWhitespace = false
  249. if (keyValueDelimiter !== -1) {
  250. const rawKey = directive.substring(0, keyValueDelimiter)
  251. const rawValue = directive.substring(keyValueDelimiter + 1)
  252. keyHasTrailingWhitespace = trimOWSEnd(rawKey) !== rawKey
  253. valueHasLeadingWhitespace = trimOWSStart(rawValue) !== rawValue
  254. key = trimOWS(rawKey)
  255. value = trimOWSStart(rawValue)
  256. } else {
  257. key = trimOWS(directive)
  258. }
  259. const malformedRestrictiveDirectiveName = getMalformedRestrictiveDirectiveName(key)
  260. if (malformedRestrictiveDirectiveName !== undefined) {
  261. output[malformedRestrictiveDirectiveName] = true
  262. continue
  263. }
  264. switch (key) {
  265. case 'min-fresh':
  266. case 'max-stale':
  267. case 'max-age':
  268. case 's-maxage':
  269. case 'stale-while-revalidate':
  270. case 'stale-if-error': {
  271. if (fromMalformedQuote || invalidNumericDirectives.has(key)) {
  272. continue
  273. }
  274. if (value === undefined || keyHasTrailingWhitespace || valueHasLeadingWhitespace) {
  275. delete output[key]
  276. invalidNumericDirectives.add(key)
  277. markInvalidCacheControlDirective(output, key)
  278. continue
  279. }
  280. if (
  281. value.length >= 2 &&
  282. value[0] === '"' &&
  283. value[value.length - 1] === '"'
  284. ) {
  285. value = value.substring(1, value.length - 1)
  286. }
  287. if (!/^[0-9]+$/.test(value)) {
  288. delete output[key]
  289. invalidNumericDirectives.add(key)
  290. markInvalidCacheControlDirective(output, key)
  291. continue
  292. }
  293. const parsedValue = Math.min(parseInt(value, 10), MAX_DELTA_SECONDS)
  294. if (key === 'min-fresh') {
  295. if (!(key in output) || output[key] < parsedValue) {
  296. output[key] = parsedValue
  297. }
  298. } else if (!(key in output) || output[key] > parsedValue) {
  299. output[key] = parsedValue
  300. }
  301. break
  302. }
  303. case 'private':
  304. case 'no-cache': {
  305. if (fromMalformedQuote) {
  306. output[key] = true
  307. break
  308. }
  309. if (value !== undefined && value.length === 0) {
  310. output[key] = true
  311. break
  312. }
  313. if (value) {
  314. // The private and no-cache directives can be unqualified (aka just
  315. // `private` or `no-cache`) or qualified (w/ a value). When they're
  316. // qualified, it's a list of headers like `no-cache=header1`,
  317. // `no-cache="header1"`, or `no-cache="header1, header2"`
  318. // If we're given multiple headers, the comma messes us up since
  319. // we split the full header by commas. So, let's loop through the
  320. // remaining parts in front of us until we find one that contains a
  321. // closing quote. We can then skip the consumed quoted-list fragments and
  322. // continue parsing like normal.
  323. // https://www.rfc-editor.org/rfc/rfc9111.html#name-no-cache-2
  324. if (value[0] === '"') {
  325. // Something like `no-cache="some-header"` OR `no-cache="some-header, another-header"`.
  326. value = trimOWSEnd(value)
  327. let fieldList = ''
  328. let lastQuotedPart = i
  329. let foundEndingQuote = false
  330. const closingQuote = findUnescapedQuote(value, 1)
  331. if (closingQuote !== -1) {
  332. fieldList = value.substring(1, closingQuote)
  333. foundEndingQuote = true
  334. } else {
  335. // Something like `no-cache="some-header, another-header"`
  336. // This can still be something invalid, e.g. `no-cache="some-header, ...`
  337. const fieldListParts = [value.substring(1)]
  338. for (let j = i + 1; j < directives.length; j++) {
  339. const nextPart = trimOWS(directives[j].value)
  340. const closingQuote = findUnescapedQuote(nextPart, 0)
  341. lastQuotedPart = j
  342. if (closingQuote !== -1) {
  343. fieldListParts.push(nextPart.substring(0, closingQuote))
  344. foundEndingQuote = true
  345. break
  346. }
  347. fieldListParts.push(nextPart)
  348. }
  349. fieldList = fieldListParts.join(',')
  350. }
  351. if (!foundEndingQuote) {
  352. output[key] = true
  353. break
  354. }
  355. i = lastQuotedPart
  356. const headers = fieldList.split(',')
  357. let validFieldNames = true
  358. for (let j = 0; j < headers.length; j++) {
  359. headers[j] = trimOWS(headers[j])
  360. if (!isValidHTTPToken(headers[j])) {
  361. validFieldNames = false
  362. }
  363. }
  364. if (!validFieldNames) {
  365. output[key] = true
  366. } else if (output[key] !== true) {
  367. if (key in output) {
  368. output[key] = output[key].concat(headers)
  369. } else {
  370. output[key] = headers
  371. }
  372. }
  373. } else {
  374. // Something like `no-cache=some-header`
  375. const fieldName = trimOWS(value)
  376. if (!isValidHTTPToken(fieldName)) {
  377. output[key] = true
  378. } else if (output[key] !== true) {
  379. if (key in output) {
  380. output[key] = output[key].concat(fieldName)
  381. } else {
  382. output[key] = [fieldName]
  383. }
  384. }
  385. }
  386. break
  387. }
  388. }
  389. // eslint-disable-next-line no-fallthrough
  390. case 'public':
  391. case 'must-revalidate':
  392. case 'proxy-revalidate':
  393. case 'immutable':
  394. case 'no-transform':
  395. case 'must-understand':
  396. case 'only-if-cached':
  397. if (fromMalformedQuote || invalidNoArgumentDirectives.has(key)) {
  398. continue
  399. }
  400. if (value !== undefined) {
  401. // These are qualified (something like `public=...`) when they aren't
  402. // allowed to be, skip all instances of the malformed directive.
  403. delete output[key]
  404. invalidNoArgumentDirectives.add(key)
  405. continue
  406. }
  407. output[key] = true
  408. break
  409. case 'no-store':
  410. output[key] = true
  411. break
  412. default:
  413. // Ignore unknown directives as per https://www.rfc-editor.org/rfc/rfc9111.html#section-5.2.3-1
  414. continue
  415. }
  416. }
  417. return output
  418. }
  419. /**
  420. * @param {string | string[]} varyHeader Vary header from the server
  421. * @returns {string[]}
  422. */
  423. function splitVaryHeader (varyHeader) {
  424. const values = Array.isArray(varyHeader) ? varyHeader : [varyHeader]
  425. const output = []
  426. for (let i = 0; i < values.length; i++) {
  427. const parts = values[i].split(',')
  428. for (let j = 0; j < parts.length; j++) {
  429. output.push(parts[j])
  430. }
  431. }
  432. return output
  433. }
  434. /**
  435. * @param {string | string[]} varyHeader Vary header from the server
  436. * @returns {boolean}
  437. */
  438. function hasVaryStar (varyHeader) {
  439. const values = splitVaryHeader(varyHeader)
  440. for (let i = 0; i < values.length; i++) {
  441. if (trimOWS(values[i]).indexOf('*') !== -1) {
  442. return true
  443. }
  444. }
  445. return false
  446. }
  447. /**
  448. * @param {string | string[]} varyHeader Vary header from the server
  449. * @param {Record<string, string | string[]>} headers Request headers
  450. * @returns {Record<string, string | string[] | null> | undefined}
  451. */
  452. function parseVaryHeader (varyHeader, headers) {
  453. if (hasVaryStar(varyHeader)) {
  454. return headers
  455. }
  456. const output = /** @type {Record<string, string | string[] | null>} */ ({})
  457. const varyingHeaders = splitVaryHeader(varyHeader)
  458. for (const header of varyingHeaders) {
  459. const trimmedHeader = trimOWS(header).toLowerCase()
  460. if (trimmedHeader.length === 0) {
  461. continue
  462. }
  463. if (!isValidHTTPToken(trimmedHeader)) {
  464. return undefined
  465. }
  466. const headerValue = headers[trimmedHeader]
  467. output[trimmedHeader] = Array.isArray(headerValue) ? headerValue.slice() : headerValue ?? null
  468. }
  469. return output
  470. }
  471. /**
  472. * @param {string | string[]} varyHeader Vary header from the server
  473. * @returns {boolean}
  474. */
  475. function isInvalidOrWildcardVaryHeader (varyHeader) {
  476. return hasVaryStar(varyHeader) || parseVaryHeader(varyHeader, {}) === undefined
  477. }
  478. /**
  479. * Note: this deviates from the spec a little. Empty etags ("", W/"") are valid,
  480. * however, including them in cached resposnes serves little to no purpose.
  481. *
  482. * @see https://www.rfc-editor.org/rfc/rfc9110.html#name-etag
  483. *
  484. * @param {string} etag
  485. * @returns {boolean}
  486. */
  487. function isEtagUsable (etag) {
  488. if (etag.length <= 2) {
  489. // Shortest an etag can be is two chars (just ""). This is where we deviate
  490. // from the spec requiring a min of 3 chars however
  491. return false
  492. }
  493. if (etag[0] === '"' && etag[etag.length - 1] === '"') {
  494. // ETag: ""asd123"" or ETag: "W/"asd123"", kinda undefined behavior in the
  495. // spec. Some servers will accept these while others don't.
  496. // ETag: "asd123"
  497. return !(etag[1] === '"' || etag.startsWith('"W/'))
  498. }
  499. if (etag.startsWith('W/"') && etag[etag.length - 1] === '"') {
  500. // ETag: W/"", also where we deviate from the spec & require a min of 3
  501. // chars
  502. // ETag: for W/"", W/"asd123"
  503. return etag.length !== 4
  504. }
  505. // Anything else
  506. return false
  507. }
  508. /**
  509. * @param {unknown} store
  510. * @returns {asserts store is import('../../types/cache-interceptor.d.ts').default.CacheStore}
  511. */
  512. function assertCacheStore (store, name = 'CacheStore') {
  513. if (typeof store !== 'object' || store === null) {
  514. throw new TypeError(`expected type of ${name} to be a CacheStore, got ${store === null ? 'null' : typeof store}`)
  515. }
  516. for (const fn of ['get', 'createWriteStream', 'delete']) {
  517. if (typeof store[fn] !== 'function') {
  518. throw new TypeError(`${name} needs to have a \`${fn}()\` function`)
  519. }
  520. }
  521. }
  522. /**
  523. * @param {unknown} methods
  524. * @returns {asserts methods is import('../../types/cache-interceptor.d.ts').default.CacheMethods[]}
  525. */
  526. function assertCacheMethods (methods, name = 'CacheMethods') {
  527. if (!Array.isArray(methods)) {
  528. throw new TypeError(`expected type of ${name} needs to be an array, got ${methods === null ? 'null' : typeof methods}`)
  529. }
  530. if (methods.length === 0) {
  531. throw new TypeError(`${name} needs to have at least one method`)
  532. }
  533. for (const method of methods) {
  534. if (!arrayIncludes(safeHTTPMethods, method)) {
  535. throw new TypeError(`element of ${name}-array needs to be one of following values: ${safeHTTPMethods.join(', ')}, got ${method}`)
  536. }
  537. }
  538. }
  539. /**
  540. * Creates a string key for request deduplication purposes.
  541. * This key is used to identify in-flight requests that can be shared.
  542. * @param {import('../../types/cache-interceptor.d.ts').default.CacheKey} cacheKey
  543. * @param {Set<string>} [excludeHeaders] Set of lowercase header names to exclude from the key
  544. * @returns {string}
  545. */
  546. function makeDeduplicationKey (cacheKey, excludeHeaders) {
  547. // Use JSON.stringify to produce a collision-resistant key.
  548. // Previous format used `:` and `=` delimiters without escaping, which
  549. // allowed different header sets to produce identical keys (e.g.
  550. // {a:"x:b=y"} vs {a:"x", b:"y"}). See: https://github.com/nodejs/undici/issues/5012
  551. const headers = {}
  552. if (cacheKey.headers) {
  553. const sortedHeaders = Object.keys(cacheKey.headers).sort()
  554. for (const header of sortedHeaders) {
  555. // Skip excluded headers
  556. if (excludeHeaders?.has(header.toLowerCase())) {
  557. continue
  558. }
  559. headers[header] = cacheKey.headers[header]
  560. }
  561. }
  562. return JSON.stringify([cacheKey.origin, cacheKey.method, cacheKey.path, headers])
  563. }
  564. module.exports = {
  565. makeCacheKey,
  566. normalizeHeaders,
  567. assertCacheKey,
  568. assertCacheValue,
  569. parseCacheControlHeader,
  570. hasInvalidCacheControlDirective,
  571. parseVaryHeader,
  572. hasVaryStar,
  573. isInvalidOrWildcardVaryHeader,
  574. isEtagUsable,
  575. assertCacheMethods,
  576. assertCacheStore,
  577. makeDeduplicationKey
  578. }