From 6588de63179559da92ff7ac7579f4648ced72533 Mon Sep 17 00:00:00 2001 From: RonniSkansing Date: Thu, 17 Sep 2026 19:36:12 +0200 Subject: [PATCH] fix malformed request in proxy using impersonation Signed-off-by: RonniSkansing --- backend/proxy/proxy.go | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/backend/proxy/proxy.go b/backend/proxy/proxy.go index 26232fd1..0145f153 100644 --- a/backend/proxy/proxy.go +++ b/backend/proxy/proxy.go @@ -251,7 +251,6 @@ func (m *ProxyHandler) HandleHTTPRequest(w http.ResponseWriter, req *http.Reques // prepare request for target server m.prepareRequestForTarget(modifiedReq, client, reqCtx.UsedImpersonation) - // execute request // execute request targetResp, err := client.Do(modifiedReq) if err != nil { @@ -742,6 +741,13 @@ func (m *ProxyHandler) prepareRequestForTarget(req *http.Request, client *http.C // note: usedImpersonation tracks if impersonation features are enabled, not if surf is used req.Header.Del(HEADER_JA4) + // remove the Content-Length header so the client transport sets the length + // once from req.ContentLength, which the request pipeline already derived + // from the buffered body. with impersonation the transport writes request + // headers as given and also frames the body length itself, so a leftover + // header sends the length twice and produces a malformed request. + req.Header.Del("Content-Length") + // setup cookie jar for redirect handling jar, _ := cookiejar.New(nil) client.Jar = jar @@ -3255,12 +3261,6 @@ func (m *ProxyHandler) normalizeRequestHeaders(req *http.Request, session *servi if secFetchDest := req.Header.Get("Sec-Fetch-Dest"); secFetchDest == "iframe" { req.Header.Set("Sec-Fetch-Dest", "document") } - - if req.Body != nil && (req.Method == "POST" || req.Method == "PUT" || req.Method == "PATCH") { - if req.Header.Get("Content-Length") == "" && req.ContentLength > 0 { - req.Header.Set("Content-Length", fmt.Sprintf("%d", req.ContentLength)) - } - } } func (m *ProxyHandler) readAndDecompressBody(resp *http.Response, usedImpersonation bool) ([]byte, bool, error) {