Ticket #196 followup: disallow spaces in uri by default
Maxim Dounin
mdounin at mdounin.ru
Tue Apr 11 15:31:10 UTC 2017
Hello!
On Sat, Apr 08, 2017 at 07:26:01PM +0000, Lukas Tribus wrote:
> in Ticket #196 [1], Maxim Dounin suggested that spaces in URI's
> could be disallowed by default.
>
> As far as I can tell, current code still does not "disallow"
> those requests (not by default and not via specific
> configuration either), is that correct?
Yes. There were no changes in this area.
> Could this be improved, as per the suggestion in the ticket?
I think it is something to be considered in 1.13.x timeframe, as
we have some plans to look into HTTP parser anyway.
I think the main question here: is it ok to just drop support for
spaces, or we have to introduce some option to preserve the old
behaviour.
--
Maxim Dounin
http://nginx.org/
More information about the nginx
mailing list