Hacker News new | ask | show | jobs
by mtkd 2795 days ago
I had a quick look at the protocol but couldn't see anything on handling that case

Regardless of the protocol - it's not unreasonable to return a 422 or 403 by default for that (malformed) request when first seen - as it would indicate that something sketchy may be going on - which can be whitelisted later