Request bodies can be gzipped with random padding so their compressed size hides the real length.
What's wrong with this entry?
A new helper can compress an outbound request body, first appending a newline and between 0 and 256 random spaces or tabs so the compressed size does not reveal the exact payload length, and setting Content-Encoding: gzip. It does nothing unless a compression-decision function is supplied at the call site and picks gzip for that URL; otherwise the request is sent as before.
- The padding is added before compression, so it affects the transmitted size rather than the content the server parses.
{ body: EP(i), headers: { "Content-Encoding": "gzip" } }
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.