Skip to content

The sensitiveHeaders HTTP2 symbol should be initialized via Symbol.for instead #36282

Description

@szmarczak

Is your feature request related to a problem? Please describe.

const kSensitiveHeaders = Symbol('nodejs.http2.sensitiveHeaders');

Currently to use the symbol we need to import it from the http2 module. A better solution would be to use Symbol.for like in the case of custom inspect symbol.

Describe the solution you'd like

-const kSensitiveHeaders = Symbol('nodejs.http2.sensitiveHeaders');
+const kSensitiveHeaders = Symbol.for('nodejs.http2.sensitiveHeaders');

Describe alternatives you've considered

None.

Activity

  1. added
    http2Issues and PRs related to the http2 subsystem.
    on Nov 27, 2020
  2. Lxxyx commented on Nov 27, 2020

    @Lxxyx
    Member

    In the documentation(https://github.com/nodejs/node/blob/master/doc/guides/using-symbols.md), there are references to how global Symbols are used.

    Global symbols should be preferred when a developer-facing interface is needed to allow behavior customization, i.e., metaprogramming.

    After trying to read the related Issue (#34091) and Pull Request(#34145).

    I think that sensitiveHeaders is a feature that developers are using in the http2 module, not a developer-facing interface, and naming it nodejs.http2.sensitiveHeaders may be a mistake.

    Details still need to be explained by @addaleax , if this is a mistake, I will file a Pull Request to fix it.

  3. szmarczak commented on Nov 27, 2020

    @szmarczak
    ContributorAuthor

    Global symbols should be preferred when a developer-facing interface is needed to allow behavior customization, i.e., metaprogramming.

    That's exactly the case here. If you declare the symbol in your headers object then the headers in that array won't be compressed. It's custom behavior, isn't it?

    I think that sensitiveHeaders is a feature that developers are using in the http2 module, not a developer-facing interface

    Following your thinking, let's revert nodejs.util.promisify.custom and nodejs.util.inspect.custom, because developers are using it in the util module.

    A module is an interface. API stands for Application Programming Interface.

  4. github-actions commented on Jun 27, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 210 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  5. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 27, 2026
  6. github-actions commented on Jul 28, 2026

    @github-actions
    Contributor

    This issue has been automatically closed after 30 days of inactivity following its stale status (no activity for a total of 120 days).
    If this is still relevant, feel free to reopen it or leave a comment with additional details so we can continue the discussion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    http2Issues and PRs related to the http2 subsystem.staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions