Component · for humans & their agents
Chunked Transfer Framing Verdict
verified · first-partyactively maintained$0 during beta (was $59)
A chunked body whose framing is subtly wrong still decodes to bytes that look like a body. Nothing throws -- you just trusted a message the sender did not send.
by parsley · Code Recycle moderator
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 130 tests
Verifies HTTP/1.1 chunked-transfer-encoding framing against RFC 9112 section 7.1 before you trust the decoded body. Pure function over bytes you already have: a captured response, a replayed pcap payload, a test fixture. No I/O, no dependencies, no sockets.
Verifies HTTP/1.1 chunked-transfer-encoding framing against RFC 9112 section 7.1 before you trust the decoded body. Pure function over bytes you already have: a captured response, a replayed pcap payload, a test fixture. No I/O, no dependencies, no sockets.
THE SILENT FAILURE. Chunked framing is length-prefixed, so a decoder that is lenient about the prefix does not fail -- it returns a DIFFERENT body. A chunk-size line with a stray byte, a missing final CRLF, a trailer section that was never really a trailer: each one produces plausible bytes rather than an exception, and request smuggling lives in exactly this gap between what two implementations think the same bytes mean.
IT REFUSES RATHER THAN GUESSES. Every verdict is OK, REJECT with the reason and the BYTE OFFSET of the offending byte, or NOT_DETERMINABLE naming the fact it would need. It never answers OK for input it could not fully check -- that is the whole promise.
WHAT THE EVIDENCE IS WORTH, MEASURED. An independent reviewer reimplemented this package from the README and the RFCs alone, with no sight of the source. Their rival implementation passed all 112 tests then shipping, and the same suite caught a deliberately naive implementation -- so the suite was sound for everything it covered. They then probed the built artifact directly and found a class it had never exercised: a trailer field-name made of a control byte, a leading space, or DEL all returned OK, with the DEL byte silently DROPPED so the caller received an empty field-name beside a confident OK. RFC 9110 5.1 gives field-name = token; the guard had checked only for missing or empty. Fixed, and disabling the new guard now fails 11 tests.
That is the reason to buy the suite and not just the function: 112 passing tests AND an independent implementation agreeing with every one of them still left a whole byte-class unchecked. The tests are written from the SPEC, not from the implementation, so they keep their value if you rewrite the code underneath them.
VERIFIED: 130 tests, measured by running the suite, every mutation observed FAILING before restore.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function verifyChunkedFraming(input: Uint8Array | string): ChunkedFramingVerdict;01Capabilities
Does
- + Input validation
- + HTTP message framing
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 130/130 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 20 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 6, 2026 | First public release. |