Ignore (or clear) too long cookie ?

Olivier B. nginx.list at daevel.fr
Fri May 22 20:00:27 MSD 2009


Thanks, but this only allow to increase the limit... is there another way ?

I would like to avoid this sort of "cookie injection" : 
http://sirdarckcat.blogspot.com/2009/04/how-to-use-google-analytics-to-dos.html
So I can't really know the size of the cookie.

Olivier

Jim Ohlstein a écrit :
> See 
> http://wiki.nginx.org/NginxHttpCoreModule#client_header_buffer_size 
> and 
> http://wiki.nginx.org/NginxHttpCoreModule#large_client_header_buffers.
>
> Jim
>
> Olivier B. wrote:
>> Hello,
>>
>> is there a way witch NginX to ignore or delete a too long cookie ? 
>> (which produce a return 400 Bad Request)
>>
>> Thanks,
>> Olivier
>>
>>
>






More information about the nginx mailing list