Hacker News new | ask | show | jobs
by tynorf 2055 days ago
I believe being lenient in accepting input is what leads to SSRF attacks (HTTP request smuggling via disagreeing `transfer-encoding` and `content-length` headers).