[PATCH] Add strict Host validation

Piotr Sikora piotr at cloudflare.com
Mon Jan 5 22:12:04 UTC 2015


Hey Maxim,

> While I agree that there is no real reason for forbidding some of
> those characters, I think that Host still should be restricted to at
> least printable ASCII characters (minus space and path separators).
>
> I can't think of any reason why would you intentionally allow control
> characters in there.

Ping... or is it still a "no"?

Best regards,
Piotr Sikora



More information about the nginx-devel mailing list