diff --git a/middleware/decompress.go b/middleware/decompress.go index 0c56176ee..7eca67953 100644 --- a/middleware/decompress.go +++ b/middleware/decompress.go @@ -7,6 +7,7 @@ import ( "compress/gzip" "io" "net/http" + "strings" "sync" "github.com/labstack/echo/v4" @@ -66,7 +67,8 @@ func DecompressWithConfig(config DecompressConfig) echo.MiddlewareFunc { return next(c) } - if c.Request().Header.Get(echo.HeaderContentEncoding) != GZIPEncoding { + // content codings are case-insensitive (RFC 9110 section 8.4.1) + if !strings.EqualFold(c.Request().Header.Get(echo.HeaderContentEncoding), GZIPEncoding) { return next(c) } diff --git a/middleware/decompress_test.go b/middleware/decompress_test.go index 63b1a68f5..bc0171b8d 100644 --- a/middleware/decompress_test.go +++ b/middleware/decompress_test.go @@ -208,3 +208,29 @@ func gzipString(body string) ([]byte, error) { return buf.Bytes(), nil } + +func TestDecompressContentEncodingCaseInsensitive(t *testing.T) { + e := echo.New() + body := `{"name":"echo"}` + gz, err := gzipString(body) + assert.NoError(t, err) + + for _, encoding := range []string{"GZIP", "Gzip"} { + t.Run(encoding, func(t *testing.T) { + req := httptest.NewRequest(http.MethodPost, "/", bytes.NewReader(gz)) + req.Header.Set(echo.HeaderContentEncoding, encoding) + rec := httptest.NewRecorder() + c := e.NewContext(req, rec) + + h := Decompress()(func(c echo.Context) error { + b, err := io.ReadAll(c.Request().Body) + if err != nil { + return err + } + return c.String(http.StatusOK, string(b)) + }) + assert.NoError(t, h(c)) + assert.Equal(t, body, rec.Body.String()) + }) + } +}