From 6d6b3615ce1f25dce0d5109679964d2f0955f3d4 Mon Sep 17 00:00:00 2001 From: KBS Date: Mon, 28 Sep 2026 20:01:58 +0900 Subject: [PATCH] fix: Reject NaN when serializing a decimal Every comparison with NaN is false, so the range check let it through and FormatFloat wrote "NaN", which parses back as a Token. RFC 9651 4.1.5 requires failing when the input is not a decimal number. --- decimal.go | 2 +- decimal_test.go | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/decimal.go b/decimal.go index 954a747..b05f9aa 100644 --- a/decimal.go +++ b/decimal.go @@ -24,7 +24,7 @@ func marshalDecimal(b io.StringWriter, d float64) error { rounded := math.RoundToEven(d/TH) * TH i, _ := math.Modf(rounded) - if i < -999999999999 || i > 999999999999 { + if math.IsNaN(d) || i < -999999999999 || i > 999999999999 { return ErrInvalidDecimal } diff --git a/decimal_test.go b/decimal_test.go index c079c6d..ea23ab1 100644 --- a/decimal_test.go +++ b/decimal_test.go @@ -1,6 +1,7 @@ package httpsfv import ( + "math" "strings" "testing" ) @@ -24,6 +25,7 @@ func TestMarshalDecimal(t *testing.T) { {-9999999999999.0, "", false}, {9999999999999.0, "", false}, {1.9, "1.9", true}, + {math.NaN(), "", false}, } var b strings.Builder