# How to send insecureHTTPParser Request with the http request node

**URL:** <https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162>\
**Category:** General\
**Created:** [2 April 2023 14:26 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162 "2023-04-02T14:26:53Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![mickym2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mickym2/32/36128_2.png) [@mickym2](https://discourse.nodered.org/u/mickym2)\
**Post date:** [2 April 2023 14:26 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/1 "2023-04-02T14:26:53Z")

</div>

Hello i'm not a WEB specialist - but I want to know, if I can send insecureHTTPParser requests with the http-Request Node. It seems that "Disable strict HTTP parsing" does not work.  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/2/820bab4de675334a706a16bd2ce47d28c4d023e3.png)

Using the search function guides me to this [thread](https://discourse.nodered.org/t/http-request-node-returning-error/71101/1) and posting #16, but as I am a dummy user - I understood nothing.

With the axios library I can set the insecureHTTPParser parameter to true and then it is possible to get data from the URL.

`axios.get(url, { insecureHTTPParser: true }).then((response) => response.data);`

So my question is: Is it possible to send this parameter somehome with the http-request node and how?

An example would be great. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [2 April 2023 16:28 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/2 "2023-04-02T16:28:53Z")

</div>

If you look at the documentation of the node it states:

> rejectUnauthorized  
> If set to `false`, allows requests to be made to https sites that use self signed certificates.

So you can put a change node before the http-request node:  
set: ` msg.rejectUnauthorized`  
with a boolean set to `false`

\*assuming this is your question.

---

<div class="post-metadata">

**Author:** ![mickym2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mickym2/32/36128_2.png) [@mickym2](https://discourse.nodered.org/u/mickym2)\
**Post date:** [2 April 2023 16:41 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/3 "2023-04-02T16:41:38Z")

</div>

No my question was how to set  
`{ insecureHTTPParser: true }`

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [2 April 2023 17:21 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/4 "2023-04-02T17:21:14Z")

</div>

What does that option do?

---

<div class="post-metadata">

**Author:** ![mickym2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mickym2/32/36128_2.png) [@mickym2](https://discourse.nodered.org/u/mickym2)\
**Post date:** [2 April 2023 17:37 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/5 "2023-04-02T17:37:57Z")

</div>

This option let you open sites which using an insecure HTTP Parser.

> **[Node.js release fixes a critical HTTP security vulnerability | Snyk](https://snyk.io/blog/node-js-release-fixes-a-critical-http-security-vulnerability/)**
>
> Today, Node.js announced a critical security vulnerability. All actively supported versions 10.x, 12.x, and 13.x of Node.js are vulnerable. We'll address how the vulnerability works what fixes are available.

So these are web sites which are "insecure" - but I do not know - what internally is wrong with these sites.

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [2 April 2023 20:04 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/6 "2023-04-02T20:04:26Z")

</div>

You tick this box

![Screenshot from 2023-04-02 21-01-52](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/3/b3d390aa82cd4861daf3ab83b10bb3c0517ce4f8.png)

The fix went into 3.0.2

p.s we don't use axios, the http-request node uses GOT.

And the problem is that the HTTP headers returned by the server do not match the spec (they break each header with only a New Line char and not a New Line + Carriage return), this allows for HTTP Request Smuggling.

---

<div class="post-metadata">

**Author:** ![mickym2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mickym2/32/36128_2.png) [@mickym2](https://discourse.nodered.org/u/mickym2)\
**Post date:** [2 April 2023 20:19 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/7 "2023-04-02T20:19:19Z")

</div>

I tried this option - but doesn't work. As I, in person, cannot test this anymore - I take it - and if really needed - I will take axios in a function node. - So many thanks so far.

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [2 April 2023 21:04 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/8 "2023-04-02T21:04:16Z")

</div>

There are tests for this option in the unit test suite that tests both the positive and negative cases so I'm pretty confident it is settings the option correctly.

But it is is possible your target server is doing something different, we would need a network capture of the request to see what the response header actually looks like to see why it's not getting parsed.

---

<div class="post-metadata">

**Author:** ![mickym2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mickym2/32/36128_2.png) [@mickym2](https://discourse.nodered.org/u/mickym2)\
**Post date:** [2 April 2023 21:31 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/9 "2023-04-02T21:31:11Z")

</div>

This URL is from a local IP address and I have not his system. So you get these errors above and the Node shows

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/5/95062d3078912bd1366beed2f41a8ea42950ce52.png)

I do not have this system - therefore I can't give any details. It is a local sytem to measure power consumption resp. production . The system may only available in Germany: EWE Elmo Smartmeter.

So I am not able to deliver here more information. I can only say that with this parameter {insecureHTTPParser: true} - we could get the information (a JSON) from the internal website, without we got these error messages.

Therefore my question was - if we can achieve the same with the http request node.

Sorry that I am not able to provide additional information.

I saw in another post - the response was:

```auto
{'bytesParsed':47,'code':'HPE_CR_EXPECTED','reason':'Missing expected CR after header value','rawPacket':{'type':'Buffer','data':[72,84,84,80,

```

or

```auto
{'bytesParsed':46,'code':'HPE_INVALID_HEADER_TOKEN','reason':'Invalid header value char','rawPacket':{'type':'Buffer','data':[72,8

```

The data buffer is exactly the same  
If look to the data - I cant see any irregularities:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/f/bfc497477593a285a9d182e4a6af20e13c3d4dd3.png)

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [7 April 2023 17:48 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/10 "2023-04-07T17:48:57Z")

</div>

If we could get all of the rawPacket in the those 2 responses we could see what's missing (all 127 bytes).

The formatted string does not show the newline and carriage return chars which is what the actual problem is.

Capture with something like wireshark or pcap would be best, or you can set the debug not to log to the console as well so it doesn't get cropped for the debug sidebar so we get all of the `rawPacket.data` array

---

<div class="post-metadata">

**Author:** ![mickym2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mickym2/32/36128_2.png) [@mickym2](https://discourse.nodered.org/u/mickym2)\
**Post date:** [7 April 2023 18:08 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/11 "2023-04-07T18:08:03Z")

</div>

I can only copy what is provided:

```auto
 {'bytesParsed':46,'code':'HPE_INVALID_HEADER_TOKEN','reason':'Invalid header value char','rawPacket':{'type':'Buffer','data':[72,84,84,80,47,49,46,49,32,50,48,48,32,79,75,10,67,111,110,116,101,110,116,45,116,121,112,101,58,32,97,112,112,108,105,99,97,116,105,111,110,47,106,115,111,110,10,67,97,99,104,101,45,67,111,110,116,114,111,108,58,32,110,111,45,115,116,111,114,101,44,32,110,111,45,99,97,99,104,101,44,32,109,117,115,116,45,114,101,118,97,108,105,100,97,116,101,44,32,109,97,120,45,97,103,101,61,48,10,80,114,97,103,109,97,58,32,110,111,45,99,97,99,104,101,10,10]}}

```

```auto
 {'bytesParsed':47,'code':'HPE_CR_EXPECTED','reason':'Missing expected CR after header value','rawPacket':{'type':'Buffer','data':[72,84,84,80,47,49,46,49,32,50,48,48,32,79,75,10,67,111,110,116,101,110,116,45,116,121,112,101,58,32,97,112,112,108,105,99,97,116,105,111,110,47,106,115,111,110,10,67,97,99,104,101,45,67,111,110,116,114,111,108,58,32,110,111,45,115,116,111,114,101,44,32,110,111,45,99,97,99,104,101,44,32,109,117,115,116,45,114,101,118,97,108,105,100,97,116,101,44,32,109,97,120,45,97,103,101,61,48,10,80,114,97,103,109,97,58,32,110,111,45,99,97,99,104,101,10,10]}}

```

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [7 April 2023 18:18 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/12 "2023-04-07T18:18:47Z")

</div>

If you fire up wireshark or TCPdump or similar, you can capture what is travelling down the wire. This is what Ben will need to understand the issue.

---

<div class="post-metadata">

**Author:** ![mickym2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mickym2/32/36128_2.png) [@mickym2](https://discourse.nodered.org/u/mickym2)\
**Post date:** [7 April 2023 18:23 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/13 "2023-04-07T18:23:51Z")

</div>

Ok - this is not possible as I dont have the hardware. I wanted to help someone else with a NodeRed Flow. - As the user is using the axios library now - and doesn't want to follow up with NodeRed, I must close this topic. But thank you all for your support so far.

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [9 April 2023 12:34 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/14 "2023-04-09T12:34:45Z")

</div>

Apologies, while the bulk of the feature made it into 3.0.2 the one key fix missed the cut so will be in 3.1.0 when it ships.

I was testing on the git head, which does have the fix and the tests.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [8 June 2023 12:35 UTC](https://discourse.nodered.org/t/how-to-send-insecurehttpparser-request-with-the-http-request-node/77162/15 "2023-06-08T12:35:01Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
