Issues
- Duplicate "Transfer-Encoding" header returned for some requestsEDGINREACH-84Antony Hruschev
- Release: Sunflower - edge-inn-reachEDGINREACH-82Resolved issue: EDGINREACH-82Antony Hruschev
- Sensitive data in logs cleanupEDGINREACH-81
- Release Ramsons BugfixEDGINREACH-80Resolved issue: EDGINREACH-80
- Sunflower 2025 R1 - Migrate AWS SDK for Java from 1.x to 2.xEDGINREACH-79Resolved issue: EDGINREACH-79Antony Hruschev
- Replace pom.xml sonar.exclusions with @SuppressWarningsEDGINREACH-78
- Release: Ramsons - edge-inn-reachEDGINREACH-76Resolved issue: EDGINREACH-76Vignesh Kalyanasundaram
- Release 3.2.6 Quesnelia (R1 2024) Service Patch #6EDGINREACH-75Resolved issue: EDGINREACH-75Julian Ladisch
- Update Spring support version for RamsonsEDGINREACH-73Resolved issue: EDGINREACH-73
- Release fix for Q CSP #1EDGINREACH-72Resolved issue: EDGINREACH-72Gurleen Kaur1
- edge-common-spring 2.4.5: AwsParamStore to support FIPS-approved crypto modulesEDGINREACH-71Resolved issue: EDGINREACH-71Gurleen Kaur1
- Release fix for Q CSP #1EDGINREACH-70Resolved issue: EDGINREACH-70Gurleen Kaur1
- edge-common-spring 2.4.4, Spring Boot 3.2.6 fixing vulnsEDGINREACH-69Resolved issue: EDGINREACH-69
- Release fix EDGINREACH-67EDGINREACH-68Resolved issue: EDGINREACH-68Gurleen Kaur1
- edge-inn-reach issueEDGINREACH-67Resolved issue: EDGINREACH-67Taras Spashchenko
- Release EDGINREACH-64, 65EDGINREACH-66Resolved issue: EDGINREACH-66Gurleen Kaur1
- Enhance HTTP Endpoint Security with TLS and FIPS-140-2 Compliant CryptographyEDGINREACH-65Resolved issue: EDGINREACH-65
- Enhance all FeignClients TLS Configurations for Secure Connections to OKAPIEDGINREACH-64Resolved issue: EDGINREACH-64Taras Spashchenko
- Release Quesnelia edge-inn-reachEDGINREACH-63Resolved issue: EDGINREACH-63Tetiana Gusar
- Update Spring version for QuesneliaEDGINREACH-62Resolved issue: EDGINREACH-62Vignesh Kalyanasundaram
- Upgrade Spring version for PoppyEDGINREACH-61Resolved issue: EDGINREACH-61Gurleen Kaur1
- Release: Poppy - edge-inn-reach (EDGINREACH)EDGINREACH-60Resolved issue: EDGINREACH-60Gurleen Kaur1
- Implement RTREDGINREACH-59Resolved issue: EDGINREACH-59Vignesh Kalyanasundaram
- Enable API-related GitHub Workflows, replace those Jenkins stagesEDGINREACH-58Resolved issue: EDGINREACH-58David Crossley
- Migrate to folio-spring-support v7.0.0EDGINREACH-56Resolved issue: EDGINREACH-56Pavankumar
- Release: Edge-inn-reach - OrchidBugFixEDGINREACH-53Resolved issue: EDGINREACH-53Giorgi Ninua
- Release: Orchid - Edge-Inn-ReachEDGINREACH-50Resolved issue: EDGINREACH-50Giorgi Ninua
- edge-inn-reach-2.0.1 fails in Nolana environmentsEDGINREACH-49Resolved issue: EDGINREACH-49Arin Suryavanshi
- Update the module to Spring boot v3.0.0 and identify issues.EDGINREACH-48Resolved issue: EDGINREACH-48Azizbek Khushvakov
- Update to Java 17.EDGINREACH-47Resolved issue: EDGINREACH-47Azizbek Khushvakov
- Logging improvement - ConfigurationEDGINREACH-46Resolved issue: EDGINREACH-46Gurleen Kaur1
- endpoint: /innreach/v2/oauth2/token produces 500EDGINREACH-45Resolved issue: EDGINREACH-45
- edge-inn-reach incomplete release process, reference environments are failingEDGINREACH-44Resolved issue: EDGINREACH-44Gurleen Kaur1
- Revise module deployment informationEDGINREACH-43Resolved issue: EDGINREACH-43Gurleen Kaur1
- bump up edge-common-spring versionEDGINREACH-42Resolved issue: EDGINREACH-42Gurleen Kaur1
- Upgrade Users interface to 16.0EDGINREACH-41Resolved issue: EDGINREACH-41Kyle Felker
- edge-inn-reach: MG releaseEDGINREACH-40Resolved issue: EDGINREACH-40Mikita Siadykh
- Release edge-inn-reach v1.0.5 fixing ZipException on 64-bit systemsEDGINREACH-37Resolved issue: EDGINREACH-37Dima Tkachenko
- edge-inn-reach - folio-spring-base update - Morning Glory 2022 R2EDGINREACH-36Resolved issue: EDGINREACH-36Gurleen Kaur1
- edge-inn-reach Spring 2.7 upgrade for Morning Glory 2022 R2EDGINREACH-35Resolved issue: EDGINREACH-35Gurleen Kaur1
- EDGINREACH (edge-inn-reach) ReleaseEDGINREACH-34Resolved issue: EDGINREACH-34Brooks Travis
- Spring4Shell Lotus/Kiwi (CVE-2022-22965)EDGINREACH-33Resolved issue: EDGINREACH-33Aleksandr Oleinik
- Spring4Shell Morning Glory (CVE-2022-22965)EDGINREACH-32Resolved issue: EDGINREACH-32Aleksandr Oleinik
- Get Bib Record D2IR API Edge Endpoint "No suitable module found" ErrorEDGINREACH-31Resolved issue: EDGINREACH-31Brooks Travis
- Logging improvementEDGINREACH-30Resolved issue: EDGINREACH-30Gurleen Kaur1
- (edge-inn-reach) Lotus R1 2022 ReleaseEDGINREACH-29Resolved issue: EDGINREACH-29Dima Tkachenko
- Remove "X-Request-Creation-Time" from list of required headers for EDGE-INN-Reach RequestsEDGINREACH-27Resolved issue: EDGINREACH-27Brooks Travis
- 3rd-party API Authentication Endpoint Should Not Require the Same Required Headers as the Rest of the D2IR API MethodsEDGINREACH-26Resolved issue: EDGINREACH-26Brooks Travis
- Edge module doesn't return payload of proxied responses from mod-inn-reachEDGINREACH-25Resolved issue: EDGINREACH-25Oleksandr Oliinyk
- Add Authorization header to D2IR API callsEDGINREACH-24Resolved issue: EDGINREACH-24Brooks Travis
50 of 70
Duplicate "Transfer-Encoding" header returned for some requests
Description
CSP Request Details
None
CSP Rejection Details
None
Potential Workaround
Don't proxy ingress for edge-inn-reach through nginx, or set up the proxy server to strip the duplicate headers.
Checklist
hideDetails
Assignee
Antony HruschevAntony HruschevReporter
Wayne SchneiderWayne SchneiderLabels
Priority
TBDDevelopment Team
VolarisRCA Group
TBDAffected releases
Quesnelia (R1 2024)Affected Institution
University of ColoradoTestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Antony Hruschev
Antony HruschevReporter
Wayne Schneider
Wayne SchneiderLabels
Priority
Development Team
Volaris
RCA Group
TBD
Affected releases
Quesnelia (R1 2024)
Affected Institution
University of Colorado
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created last month
Updated last month
Activity
Show:
Gurleen Kaur1
made 2 changeslast month
Assignee
Unassigned
Antony Hruschev
Labels
None
back-end
Wayne Schneider
created the Issuelast month
It appears that edge-inn-reach may be producing a duplicate “Transfer-Encoding” header in HTTP responses under some circumstances. Here are the headers for a response to the
verifypatron
request:HTTP/1.1 200 cache-control: no-cache, no-store, max-age=0, must-revalidate connection: keep-alive date: Wed, 26 Mar 2025 18:47:44 GMT expires: 0 keep-alive: timeout=60 pragma: no-cache transfer-encoding: chunked vary: Access-Control-Request-Headers vary: Access-Control-Request-Method vary: Origin x-content-type-options: nosniff x-frame-options: DENY x-xss-protection: 0 Content-Type: application/json Transfer-Encoding: chunked
Note both
transfer-encoding: chunked
andTransfer-Encoding: chunked
This can cause issues for clients and upstream proxies that are more strict about header checking.