@@ -225,6 +225,46 @@ class GzipFilterSpec extends PlaySpecification with DataTables {
225225 threshold = 18
226226 ) { implicit app => checkGzippedBody(makeGzipRequest(app), " these are 18 bytes" )(using app.materializer) }
227227
228+ " weaken ETag header when gziping a response" in withApplication(
229+ Ok (" hello" ).withHeaders(ETAG -> " \" abc123\" " )
230+ ) { implicit app =>
231+ val result = makeGzipRequest(app)
232+ checkGzippedBody(result, " hello" )(using app.materializer)
233+ header(ETAG , result) must beSome(" W/\" abc123\" " )
234+ }
235+
236+ " not weaken ETag header when not gziping a response" in withApplication(
237+ Ok (" hello" ).withHeaders(ETAG -> " \" abc123\" " )
238+ ) { implicit app =>
239+ val result = route(app, FakeRequest ().withHeaders(ACCEPT_ENCODING -> " identity" )).get
240+ checkNotGzipped(result, " hello" )(using app.materializer)
241+ header(ETAG , result) must beSome(" \" abc123\" " )
242+ }
243+
244+ " not add ETag header when gziping a response without an ETag header" in withApplication(
245+ Ok (" hello" )
246+ ) { implicit app =>
247+ val result = makeGzipRequest(app)
248+ checkGzippedBody(result, " hello" )(using app.materializer)
249+ header(ETAG , result) must beNone
250+ }
251+
252+ " not modify ETag header when gziping a response with an already weak ETag header" in withApplication(
253+ Ok (" hello" ).withHeaders(ETAG -> " W/\" abc123\" " )
254+ ) { implicit app =>
255+ val result = makeGzipRequest(app)
256+ checkGzippedBody(result, " hello" )(using app.materializer)
257+ header(ETAG , result) must beSome(" W/\" abc123\" " )
258+ }
259+
260+ " remove invalid ETag header when gzipping a response" in withApplication(
261+ Ok (" hello" ).withHeaders(ETAG -> " abc123" ) // unquoted ETag value; a common violation of RFC 7232
262+ ) { implicit app =>
263+ val result = makeGzipRequest(app)
264+ checkGzippedBody(result, " hello" )(using app.materializer)
265+ header(ETAG , result) must beNone
266+ }
267+
228268 val body = Random .nextString(1000 )
229269
230270 " a streamed body" should {
0 commit comments