Skip to content

Allow custom FalconClient user agents - #326

Merged
carlosmmatos-cs merged 2 commits into
CrowdStrike:mainfrom
ting-hong-shieh:agent/configurable-user-agent
Aug 13, 2026
Merged

carlosmmatos-cs merged 2 commits into
CrowdStrike:mainfrom
ting-hong-shieh:agent/configurable-user-agent

Conversation

@ting-hong-shieh

Copy link
Copy Markdown
Contributor

Summary

Add an optional userAgentOverride setting to FalconClientOptions.

When set, FalconJS prepends the integration identifier to its existing SDK identifier. The same header is used for OAuth token requests and subsequent API requests. For example:

example-integration/1.0.0 falconjs/0.7.0

The default remains falconjs/0.7.0 when no override is provided. The README now documents the option and resulting header.

Closes #221.

Validation

  • pnpm run build
  • pnpm run lint
  • Runtime assertions for the default and overridden headers

@ting-hong-shieh
ting-hong-shieh marked this pull request as ready for review August 13, 2026 15:06
Reject overrides containing spaces in the wrong place, token delimiters,
or CR/LF before they reach the User-Agent header. Trim surrounding
whitespace so a padded value composes cleanly, and escape the offending
value in the thrown error to avoid log injection.
@carlosmmatos-cs

carlosmmatos-cs commented Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Thanks for this @ting-hong-shieh . Nice change that was needed.

I pushed one commit on top of yours (eb930c5) that validates userAgentOverride before it reaches the header. As written, the override goes into the header verbatim, so a value with a stray space, a token delimiter like ;, or a \r\n would either produce a malformed User-Agent or, with a custom fetchApi, open the door to header injection. Standard fetch happens to reject the CRLF case, but the SDK shouldn't rely on the transport to catch that for us.

What the commit does:

  • trims surrounding whitespace so a padded value still composes cleanly
  • validates the result against the RFC 9110 product-token grammar (§5.6.2 tchar, §10.1.5 product = token["/"token], single-space separators) and throws a clear error naming userAgentOverride when it doesn't match
  • escapes the offending value in that error so a CRLF payload can't inject fake log lines

Valid identifiers like example-integration/1.0.0 behave exactly as before, and the default stays falconjs/0.7.0. Build, lint, and format all pass.

One call I made: it throws on bad input rather than silently falling back to the default, since a wrong User-Agent is easy to miss otherwise. Happy to switch it to warn-and-fallback if you'd prefer that.

@ting-hong-shieh

Copy link
Copy Markdown
Contributor Author

Hi @carlosmmatos-cs, thanks for adding the validation. Throwing on invalid input makes sense to me and is preferable to silently falling back. The trimming behavior and product-token validation look good.

@carlosmmatos-cs
carlosmmatos-cs merged commit 4a55d50 into CrowdStrike:main Aug 13, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow setting FalconClient's user-agent

2 participants