> better constrain IP-literal validation in ngx_http_validate_host()
> The existing validation in ngx_http_validate_host() would allow a IP-literal
> such as "[]" which is invalid according to RFC 3986 (See Appendix A.
> for the Collected ABNF). This format is intended for IPv6 and IPv-future not
> IPv4.

We've considered doing more strict checks when introducing IPv6 
literals in e7db97bfac25 (http://hg.nginx.org/nginx/rev/e7db97bfac25), 
yet decided that:

- it doesn't add anything to security,
- and may actually harm some future workloads, such as using 
  things like [unix:/path/to/unix.socket].

In particular, it doesn't looks like permitting [] can be 
a problem.

Do you think that introducing more strict checks can be 
beneficial?  Could you please outline reasons?


Maxim Dounin

