Skip to content

A leading UTF-8 BOM hides the first SSE event or error #413

Description

@sylvesterkaczmarek

The SSE state machine treats a leading U+FEFF byte-order mark as part of the first field name. A stream beginning with \uFEFFevent: message_start loses that event, while \uFEFFevent: error can hide a streamed error. When data: is the first field, the first payload is discarded instead.

A single leading BOM is explicitly allowed by the event-stream grammar and removed by its UTF-8 decoding rule: https://html.spec.whatwg.org/multipage/server-sent-events.html#event-stream-interpretation

Reproduced with one-byte InputStream reads, including the three bytes of the BOM, LF/CRLF/CR line endings, both normal and raw SSE handlers, and an error event. Six new cases fail on current main; a control verifies that non-leading or repeated U+FEFF characters are not stripped.

Ignore exactly one BOM only when interpreting the first line. Preserve original raw lines for middleware and leave U+FEFF inside payloads or later lines untouched. No general SSE filtering or end-of-stream policy changes are needed.

Reproduced on main at 6324b459fcde08738a255adcd88439b68851d512.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions