@@ -205,6 +205,29 @@ def test_multipart_headers_include_content_type() -> None:
205205 )
206206
207207
208+ @pytest .mark .parametrize (
209+ ("content_type" , "file_headers" ),
210+ [
211+ ("text/plain\r " , {}),
212+ (None , {"X-Test\t " : "value" }),
213+ (None , {"X-Test" : "value\n " }),
214+ ],
215+ )
216+ def test_multipart_rejects_invalid_file_headers (content_type : str | None , file_headers : dict [str , str ]) -> None :
217+ files = {"file" : ("test.txt" , b"<file content>" , content_type , file_headers )}
218+
219+ with pytest .raises (ValueError , match = "Invalid .*multipart header" ):
220+ httpx2 .Request ("POST" , "https://www.example.com/" , files = files )
221+
222+
223+ @pytest .mark .parametrize ("control_character" , ["\x00 " , "\x01 " , "\x08 " , "\x1f " , "\x7f " ])
224+ def test_multipart_rejects_control_characters_in_file_header_values (control_character : str ) -> None :
225+ files = {"file" : ("test.txt" , b"<file content>" , None , {"X-Test" : f"value{ control_character } " })}
226+
227+ with pytest .raises (ValueError , match = "Invalid control character in multipart header value" ):
228+ httpx2 .Request ("POST" , "https://www.example.com/" , files = files )
229+
230+
208231def test_multipart_encode (tmp_path : typing .Any ) -> None :
209232 path = str (tmp_path / "name.txt" )
210233 with open (path , "wb" ) as f :
0 commit comments