#ClientRequest
It always bothers me when I have to paint something not anatomically correct, to fulfil a client request. But: If it makes them happy, I shall make those teeth longer. Who am I to judge! Album artwork for Marco Minnemann. #sciart #wolf #teeth #marcominnemann #albumartwork #canine #clientrequest #art
February 18, 2025 at 11:48 AM
A Quiet Moment!
Posed nude for Dennis.
#Nude #ClientRequest #Magazine
March 28, 2026 at 3:51 PM
Let's nerd about request interception in Node.js.

With the new architecture I'm working on, you'd be able to intercept any HTTP request using the same interceptor. No reason to distinguish between ClientRequest or XHR or fetch. Pretty neat. 1/x
March 4, 2026 at 7:46 PM
PSA: The node:http get and request methods will soon be available for use on Cloudflare Workers with nodejs_compat mode github.com/cloudflare/w...
put http and https modules behind compat flag by anonrig · Pull Request #4456 · cloudflare/workerd
This pull-request enables the following modules and functions behind a compat flag node:_http_agent Agent globalAgent node:_http_client ClientRequest node:_http_common _checkIsHttpToken _ch...
github.com
July 18, 2025 at 3:34 PM
What I wish is that we designed proper server-side request/response primitives. Maybe going as low as HttpMessage. Not the butchered fetch, not clunky ClientRequest or IncomingMessage, but an actual answer to the real problem that, sadly, remains unsolved.
August 16, 2026 at 2:46 PM
Historically, this has been unsolvable. We did make a good progress on this by bringing the interception to the socket level so at least ClientRequest writes on "connect" will function as expected in v3.0.
September 10, 2026 at 6:55 PM
I am absolutely confused. In Node.js, if the server starts streaming a response and then the response stream errors, which events will ClientRequest emit?

error on request? error on IncomingMessage? Both?

🫠
August 7, 2025 at 4:31 PM
My firehose subscriber occasionally just randomly starts returning this error and I have no idea why. Any thoughts?
August 21, 2025 at 6:45 PM
A client of ours is looking for a hydro jet hottub.

Clients requirements:
A UK business
Must be a 5 or 6 seater
Solid unit
Price range £2k to £4k

#ClientRequest #ukbusiness

Please comment below or tag relevant business
August 19, 2024 at 12:02 PM
"Please make the following items mustard in colour" #clientrequest Googling images now for Mustard Gas to get the exact shade
November 13, 2024 at 4:00 AM
Timed out while waiting for response to ClientRequest. Waited 0:00:05 seconds You Should do that ...

https://community.openai.com/t/timed-out-while-waiting-for-response-to-clientrequest-waited-005-seconds/1249363#post_2

Result Details
Awakari App
awakari.com
May 12, 2025 at 9:59 AM
Https://api.openai.com/v1/chat/completions failed, reason: unable to get local issuer certificate
I am getting the same error Error calling Groq API: FetchError: request to failed, reason: unable to get local issuer certificate [0] at ClientRequest. (C:\New folder\user-story-to-tests\node_modules\node-fetch\src\index.js:108:11) [0] at ClientRequest.emit (node:events:520:35) [0] at emitErrorEvent (node:_http_client:107:11) [0] at TLSSocket.socketErrorListener (node:_http_client:574:5) [0] at TLSSocket.emit (node:events:508:28) [0] at emitErrorNT (node:internal/streams/destroy:170:8) [0] at emitErrorCloseNT (node:internal/streams/destroy:129:3) [0] at process.processTicksAndRejections (node:internal/process/task_queues:90:21) { [0] type: ‘system’, [0] errno: ‘UNABLE_TO_GET_ISSUER_CERT_LOCALLY’, [0] code: ‘UNABLE_TO_GET_ISSUER_CERT_LOCALLY’, [0] erroredSysCall: undefined [0] } [0] LLM error: FetchError: request to failed, reason: unable to get local issuer certificate [0] at ClientRequest. (C:\New folder\user-story-to-tests\node_modules\node-fetch\src\index.js:108:11) [0] at ClientRequest.emit (node:events:520:35) [0] at emitErrorEvent (node:_http_client:107:11) [0] at TLSSocket.socketErrorListener (node:_http_client:574:5) [0] at TLSSocket.emit (node:events:508:28) [0] at emitErrorNT (node:internal/streams/destroy:170:8) [0] at emitErrorCloseNT (node:internal/streams/destroy:129:3) [0] at process.processTicksAndRejections (node:internal/process/task_queues:90:21) { [0] type: ‘system’, [0] errno: ‘UNABLE_TO_GET_ISSUER_CERT_LOCALLY’, [0] code: ‘UNABLE_TO_GET_ISSUER_CERT_LOCALLY’, [0] erroredSysCall: undefined [0] } What can we do for this error?
community.openai.com
November 4, 2025 at 11:01 AM
見えないSplinter:隠されたNode.jsの欠陥が毎週1億6000万のセキュリティガードをバイパスする方法

Node.jsエコシステム内で、HTTPクライアントの基本的なロジックに関連する脆弱性が発見されました。これにより、脅威アクターがリクエスト分割に対する既存の防御をバイパスすることが可能になります。r3veriiというモニカーで活動するMartino…
見えないSplinter:隠されたNode.jsの欠陥が毎週1億6000万のセキュリティガードをバイパスする方法
Node.jsエコシステム内で、HTTPクライアントの基本的なロジックに関連する脆弱性が発見されました。これにより、脅威アクターがリクエスト分割に対する既存の防御をバイパスすることが可能になります。r3veriiというモニカーで活動するMartino Spagnoloは、Node.jsコアチームがこの問題を彼らの脅威モデルの違反として分類することを拒否した後、包括的な分析を発表しました。これは、ヘッダーを注入し、単一の接続内で2番目のリクエストを偽造するという危険な能力のロックを解除するメカニズムに関するものです。 この困難の起源は2018年に遡ります。当時、CVE-2018-12116脆弱性は、latin1エンコーディングの特性を利用することで、制御文字の流入を許可していました。これに対応して、開発者はhttp.request内のリクエストパスに対する検証プロトコルを制度化し、\u0021~\u00ff範囲外の文字を厳密に禁止しました。しかし、この保護機構はClientRequestオブジェクトのインスタンス化の正確な瞬間にのみ発動されました。その後、pathプロパティは平凡で可変なフィールドとして放置され、追加の検証はまったくありませんでした。 その後の調査により、リクエスト生成後にclientRequest.pathが変更された場合、この重要な検証が効果的にバイパスされることが明らかになりました。HTTPストリングの合成中、_implicitHeaderメソッドは現在のpathの値を盲目的に消費し、2次的なフィルタリングの対象にしません。その結果、特に\r\nなどの有害な制御シーケンスは、TCPストリームに直接妨害されずに通過します。 影響は自然に送信されたペイロードに応じて異なります。最も基本的な形では、悪意のある人物は補足的なHTTPヘッダーを注入し、HostまたはAuthorizationディレクティブを秘密裏に置き換える可能性があります。より深刻なシナリオでは、敵対者がヘッダーを完全に終了し、偽造されたリクエストボディを追加することができ、元の呼び出しの意味を根本的に変更します。最も悲劇的な順列は、明確なHTTPリクエスト分割に至り、疑わない相手方サーバーが1つになりすまして2つの独立したHTTPリクエストを受け取ります。 研究者は広く使われているライブラリを綿密に監査し、この防御不可能なTime-of-Check to Time-of-Use(TOCTOU)の深淵に悩まされた7つの著名なプロジェクトを暴露しました。これらの被害者の中には、node-http-proxy、http-proxy-middleware、superagent、request、および@hapi/wreckが含まれます。それらの総ダウンロード量は1週間で驚くべき1億6000万を超えています。アーキテクチャ上の欠陥は全体を通じて均一に一貫しています。ライブラリはClientRequestをインスタンス化し、次にヘッダーの送出前に外部ハンドラーにオブジェクトを時期尚早に譲り渡します。ハンドラーがその後、ユーザー提供データに基づいてpathを変更する場合、フィルタリング機構は完全に回避されます。 特定のユーティリティは、異なるアーキテクチャの利点により幸運にもこの危険を回避しました。axiosはfollow-redirectsを活用し、内部ClientRequestへのアクセスを厳密に保持しています。gotはオブジェクトの外部露出に先立ってヘッダーを送出します。一方、undiciとネイティブfetch APIは、可変pathプロパティを完全に持たないHTTPスタックのカスタム実装を採用しています。 HackerOneプログラムを通じて通信する中で、Node.jsの先鋒は、この動作が現在の運用ロジックと完全に一致していると主張し、それを正当な脆弱性として認識することを拒否しました。彼らの視点から、責任の重荷は、インスタンス化後のpath変更を許可する外部ライブラリの上に正確に存在します。この研究の設計者はこの評価に激しく異議を唱え、脆弱なエコシステムの莫大な規模を強調し、完全に機能する概念実証を披露しました。 基本的な万能薬として、パスがリクエスト文字列の合成の直前に2次検証を受けるか、または代わりにpathプロパティが厳密な検証ロジックを備えたセッターを介して強化されることが提案されています。現在コア修正は予想されていませんが、開発者はclientRequest.pathへのあらゆる割り当てについてコードベースを綿密に調べるよう強く促され、これらの値がサニタイズされていないユーザー入力から導出されないことを厳密に検証する必要があります。 翻訳元:
blackhatnews.tokyo
March 4, 2026 at 7:37 AM
I cannot wait for Undici to get bigger adoption. ClientRequest is still heavily used, and Undici's agent has no effect on it (rightfully). Handling requests on async_hooks level is extremely cumbersome and every step screams at you that the API wasn't built for that.
January 19, 2026 at 10:29 PM
In the upcoming version of MSW we are making custom HTTP agent support better by fixing a bug that prevented http.Agent instances from being correctly used for HTTPS requests.

More details here:
github.com/mswjs/inter...
fix(ClientRequest): support `http.Agent` instances as agents for `https` requests by kettanaito · Pull Request #737 · mswjs/interceptors
Fixes this._getSession is not a function while use HttpsProxyAgent #675 Changes MockHttpsAgent now performs an instance check for http.Agent since HTTP agents are valid agents for https.request().
github.com
July 29, 2025 at 2:36 PM
Here's a non-trivial issue for the Node.js side of MSW:
github.com/mswjs/interc...

TL;DR we need to invoke "addRequest" of custom request agents but that taps into "super.addRequest" that initiates the actual network connection (addRequest -> createSocket -> createConnection).
fix(ClientRequest): support `addRequest` from custom http agents by kettanaito · Pull Request #666 · mswjs/interceptors
Originates from Bypassed requests miss cookie headers with axios + axios-cookiejar-support msw#2338
github.com
November 3, 2024 at 7:16 PM