Re: Rejecting messages with illegal characters in header fields (was Re: h2 header field names)

On 5 September 2014 04:20, Martin Thomson <martin.thomson@gmail.com> wrote:

> On 3 September 2014 23:53, Julian Reschke <julian.reschke@gmx.de> wrote:
> > Wait! Percent-Encoded?
>
> OK, then we treat header field values containing forbidden characters
> as malformed?  That invalidates a non-zero number of requests that our
> various test runs have detected, I think.  Are we OK with that?  I am,
> but I'm not as naturally conservative as some folks here.
>
>
Sounds good to me.​


-- 
  Matthew Kerwin
  http://matthew.kerwin.net.au/

Received on Thursday, 4 September 2014 23:11:11 UTC

Follow Lee on X/Twitter - Father, Husband, Serial builder creating AI, crypto, games & web tools. We are friends :) AI Will Come To Life!

Check out: eBank.nz (Art Generator) | Netwrck.com (AI Tools) | Text-Generator.io (AI API) | BitBank.nz (Crypto AI) | ReadingTime (Kids Reading) | RewordGame | BigMultiplayerChess | WebFiddle | How.nz | Helix AI Assistant