Ticket #196 followup: disallow spaces in uri by default

Maxim Dounin mdounin at mdounin.ru
Tue Apr 11 15:31:10 UTC 2017


Hello!

On Sat, Apr 08, 2017 at 07:26:01PM +0000, Lukas Tribus wrote:

> in Ticket #196 [1], Maxim Dounin suggested that spaces in URI's 
> could be disallowed by default.
> 
> As far as I can tell, current code still does not "disallow" 
> those requests (not by default and not via specific 
> configuration either), is that correct?

Yes.  There were no changes in this area.

> Could this be improved, as per the suggestion in the ticket?

I think it is something to be considered in 1.13.x timeframe, as 
we have some plans to look into HTTP parser anyway.

I think the main question here: is it ok to just drop support for 
spaces, or we have to introduce some option to preserve the old 
behaviour.

-- 
Maxim Dounin
http://nginx.org/


More information about the nginx mailing list